logo

GPU mining malware spreads via SEO poisoning, AI chatbots

ID: 58f6cd2d-0219-5ee8-bc1b-d6c9b537e249

STIX ID: report--58f6cd2d-0219-5ee8-bc1b-d6c9b537e249

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Ionut Ilascu

...
...

Microsoft researchers uncovered a targeted cryptojacking campaign that uses SEO poisoning and AI chatbot link manipulation to serve trojanized utility installers; the payload drops a malicious DLL which installs ScreenConnect for persistent remote access, employs process hollowing and Defender exclusion for stealth, and deploys GPU miners (gminer, lolMiner, SRBMiner‑MULTI) optimized to maximize mining yield on high-performance systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.