GPU mining malware spreads via SEO poisoning, AI chatbots
A cryptojacking campaign utilizing SEO poisoning and AI chatbot manipulation is spreading through malicious downloads of popular system utilities. The campaign leverages a ZIP archive containing a malicious DLL and a ScreenConnect remote access tool to gain persistent access to compromised systems, ultimately utilizing GPU mining software to generate cryptocurrency. This campaign is notable for its targeted approach to maximize GPU mining yield.
The campaign began with users searching for legitimate system utilities like CrystalDiskInfo and HWMonitor, which were then redirected to malicious download pages through SEO poisoning. Microsoft researchers discovered that some users were also receiving these malicious links within AI chatbot responses when requesting software recommendations. The malicious downloads, hosted on the gleeze[.]com subdomain, contained a legitimate utility alongside a malicious DLL that automatically installed the ScreenConnect remote access tool. Following initial access, the threat actor deployed SimpleRunPE.exe, employing process hollowing techniques to disguise its activity and evade detection, including attempts to impersonate legitimate Microsoft binaries and bypass Microsoft Defender. The malware then executed GPU mining modules, including gminer, lolMiner, and SRBMiner-MULTI, to maximize cryptocurrency generation.