logo

Sophisticated GPU Cryptojacking Campaign Surfaced by Microsoft Experts

ID: ab602f0e-bf7d-5a08-ba7b-48dd680380c7

STIX ID: report--ab602f0e-bf7d-5a08-ba7b-48dd680380c7

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Ddos

...
...

Microsoft Defender experts report a targeted GPU cryptojacking campaign that poisons search engine and AI-assisted results to distribute trojanized utilities (impersonating tools like CrystalDiskInfo/FurMark). The malware uses DLL sideloading (autorun.dll), process hollowing of signed binaries (e.g., MSBuild.exe), multiple persistence mechanisms (registry Run keys, three scheduled tasks), ScreenConnect abuse for secondary payload delivery, anti-analysis checks and self-repair routines, and dynamically streams popular GPU miners (gminer/lolMiner) to maximize GPU mining yield on powerful gaming rigs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.