Microsoft reported an active cryptojacking campaign that uses poisoned search results and, in some cases, AI chatbot software recommendations to steer users to attacker-controlled sites impersonating popular utilities including CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear. The operation appears to target hardware enthusiasts and other users with high-performance GPUs, delivering ZIP archives that bundle legitimate applications with malicious autorun.dll files for DLL sideloading. Microsoft said it has identified more than 150 malicious domains tied to the campaign since March 2026.
After execution, the malware abuses ScreenConnect for persistent remote access, uses a custom loader with process hollowing into Microsoft-signed .NET binaries, adds Microsoft Defender exclusions, and performs anti-analysis and host reconnaissance before downloading miners such as gminer, lolMiner, and SRBMiner-MULTI. The malware can pause mining during user or GPU activity to reduce detection, and Microsoft warned that the ScreenConnect foothold could also support follow-on actions including data theft, lateral movement, or ransomware. Microsoft said Defender detected and blocked related activity and highlighted mitigations including cloud-delivered protection, EDR in block mode, network and web protection, SmartScreen, and attack surface reduction rules.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-26, Microsoft published details of the campaign, describing DLL sideloading, ScreenConnect abuse for persistence, process hollowing into Microsoft-signed .NET binaries, and deployment of GPU-focused miners. Microsoft also shared C2 and IOC details, said Defender detected and blocked associated activity, and recommended mitigations including cloud-delivered protection, EDR in block mode, SmartScreen, and attack surface reduction rules.
Microsoft linked an active cryptojacking campaign to more than 150 malicious domains observed since March 2026. The operation used SEO poisoning and, in some cases, AI chatbot software recommendations to lure users to fake utility download sites targeting systems with high-performance GPUs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcetomshardware.com
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.