GPUGate is a malware strain observed in 2025 that is delivered via trojanized GitHub Desktop installers. Reporting states it was promoted through malvertising, including abuse of Google Ads, and used fake GitHub commits as part of the lure chain. The malware has been described as using hardware-specific decryption, and campaigns were reported as targeting IT firms and victims in Western Europe. High-confidence reporting in the provided content links GPUGate to malicious GitHub Desktop implants, Google Ads abuse for distribution, and targeting in Western Europe. No specific threat actor attribution or concrete indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware campaign leveraging Google Ads and fake GitHub commit references/URLs to target IT firms; no further details in excerpt.
Malware that implants itself in GitHub Desktop, uses hardware-specific decryption, and abuses Google Ads to target users in Western Europe.
Malware that implants itself via trojanized GitHub Desktop installers, uses hardware-specific decryption to evade detection, and abuses Google Ads for distribution, targeting Western Europe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.