Sophisticated GPU Cryptojacking Campaign Surfaced by Microsoft Experts
ID: ab602f0e-bf7d-5a08-ba7b-48dd680380c7
STIX ID: report--ab602f0e-bf7d-5a08-ba7b-48dd680380c7
Feed Name: securityonline.info
Microsoft Defender experts report a targeted GPU cryptojacking campaign that poisons search engine and AI-assisted results to distribute trojanized utilities (impersonating tools like CrystalDiskInfo/FurMark). The malware uses DLL sideloading (autorun.dll), process hollowing of signed binaries (e.g., MSBuild.exe), multiple persistence mechanisms (registry Run keys, three scheduled tasks), ScreenConnect abuse for secondary payload delivery, anti-analysis checks and self-repair routines, and dynamically streams popular GPU miners (gminer/lolMiner) to maximize GPU mining yield on powerful gaming rigs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
