GPU mining malware spreads via SEO poisoning, AI chatbots
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. [...]
AI Analysis
Technical Summary
This ongoing cryptojacking campaign targets systems with powerful GPUs by poisoning search engine results and influencing AI chatbot responses to direct users to attacker-controlled domains hosting malicious downloads. The downloads appear as legitimate utility software but include a malicious DLL that installs the ScreenConnect remote management tool for persistent access. The malware employs process hollowing into signed Windows utilities and uses multiple persistence mechanisms. It also evades detection by excluding itself from Microsoft Defender and terminating if analysis tools or virtual machines are detected. After establishing persistence, the malware downloads one of three GPU mining programs (gminer, lolMiner, SRBMiner-MULTI) to maximize mining efficiency on compromised devices.
Potential Impact
Infected systems provide attackers with persistent remote access via ScreenConnect, enabling further malware deployment. The primary impact is unauthorized cryptocurrency mining using the victim's GPU resources, which can degrade system performance and increase operational costs. The campaign is notable for its targeted approach to maximize GPU mining yield rather than broad infection volume. There is no indication of data theft or direct system destruction from the provided information.
Mitigation Recommendations
No official patch is available as this is a malware campaign rather than a software vulnerability. Users should avoid downloading utilities from untrusted sources and verify URLs carefully. Organizations should monitor for the presence of ScreenConnect installations not authorized by IT, and check for persistence mechanisms and process hollowing behaviors described. Microsoft Defender exclusions should be audited to detect unauthorized additions. Since the malware evades detection by checking for analysis environments, employing layered detection strategies including behavioral analysis is recommended. Review the Microsoft advisory linked in the source for indicators of compromise and further guidance.
GPU mining malware spreads via SEO poisoning, AI chatbots
Description
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This ongoing cryptojacking campaign targets systems with powerful GPUs by poisoning search engine results and influencing AI chatbot responses to direct users to attacker-controlled domains hosting malicious downloads. The downloads appear as legitimate utility software but include a malicious DLL that installs the ScreenConnect remote management tool for persistent access. The malware employs process hollowing into signed Windows utilities and uses multiple persistence mechanisms. It also evades detection by excluding itself from Microsoft Defender and terminating if analysis tools or virtual machines are detected. After establishing persistence, the malware downloads one of three GPU mining programs (gminer, lolMiner, SRBMiner-MULTI) to maximize mining efficiency on compromised devices.
Potential Impact
Infected systems provide attackers with persistent remote access via ScreenConnect, enabling further malware deployment. The primary impact is unauthorized cryptocurrency mining using the victim's GPU resources, which can degrade system performance and increase operational costs. The campaign is notable for its targeted approach to maximize GPU mining yield rather than broad infection volume. There is no indication of data theft or direct system destruction from the provided information.
Mitigation Recommendations
No official patch is available as this is a malware campaign rather than a software vulnerability. Users should avoid downloading utilities from untrusted sources and verify URLs carefully. Organizations should monitor for the presence of ScreenConnect installations not authorized by IT, and check for persistence mechanisms and process hollowing behaviors described. Microsoft Defender exclusions should be audited to detect unauthorized additions. Since the malware evades detection by checking for analysis environments, employing layered detection strategies including behavioral analysis is recommended. Review the Microsoft advisory linked in the source for indicators of compromise and further guidance.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/gpu-mining-malware-spreads-via-seo-poisoning-ai-chatbots/","fetched":true,"fetchedAt":"2026-05-27T21:33:33.259Z","wordCount":858}
Threat ID: 6a17632de29bf47b50f09ad8
Added to database: 5/27/2026, 9:33:33 PM
Last enriched: 5/27/2026, 9:33:41 PM
Last updated: 5/29/2026, 6:46:24 PM
Views: 32
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.