惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
MongoDB | Blog
MongoDB | Blog
Martin Fowler
Martin Fowler
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
B
Blog
U
Unit 42
B
Blog RSS Feed
D
DataBreaches.Net
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
腾讯CDC
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
博客园 - 聂微东
MyScale Blog
MyScale Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
Engineering at Meta
Engineering at Meta

Latest from Tom's Hardware

Our experts review your astonishing PC builds and setups in Rig Rundown — from wall-mounted setups to a system… News outlets are blocking Wayback Machine from archiving their pages — 23 outlets concerned AI companies might abuse fair use and use it to train their models Mark Zuckerberg reportedly working on AI clone of himself — Meta insiders claim 3D photoreal animated Zuck will be able to engage with employees on his behalf Score a massive $700 off this 4K-ready Lenovo gaming PC with an RTX 5070 Ti, now just $1,899 — epic Legion Tower 5i pre-built ships with a 20-core Intel CPU, 32GB DDR5 and a 2TB SSD Pay $1,349.99 for Gigabyte's Aero X16 laptop and save $300 on this 32GB beast with RTX 5070 graphics —… Veteran Windows dev shows off AI running on 47-year-old PDP11 with 6 MHz CPU and 64KB of RAM — 'gloriously absurd' project runs transformer model written in PDP-11 assembly language Half of all US employees now use artificial intelligence at work, crossing landmark threshold for first time — Gallup data shows daily and weekly usage hitting all-time high of 28% in Q1 2026, with 65% feeling positive about its impact on productivity China has spent 3.6 times more than the US on chipmaking subsidies over the past decade — $142 billion and counting, easily outweighs CHIPS Act FAA approves military use of drone-killing laser weapons in US airspace — decision comes after it was decided ‘systems do not present an increased risk to the flying public’ Nvidia says AI cuts 10-month, eight-engineer GPU design task to overnight job — company is still 'a long way' from AI designing chips without human input Small Missouri town ousts half its city council after $6 billion AI data center approval — petition calls for mayor's removal as frustration (and violence) over AI data centers mounts New tech can see a CPU's transistors in action — terahertz radiation can potentially steal data as a chip is… Intel's Nova Lake CPUs gear up to seize AMD’s 3D V-Cache gaming throne — early leak points to up to 52 cores, blazing DDR5-8000 support, and massive 175W TDP Acer Predator GX850 SFX power supply review: Solid electrical performance with good efficiency NZXT to cough up $3.45 million over 'predatory' Flex PC rental scheme in RICO class-action settlement — in-debt customers to get up to $5,000 of relief, eligible renters to be granted ownership Bulbous 15x fan PC case side panel dubbed the ‘Superdome’ lowers temps by 20 degrees —  $600 worth of Noctua fans arrayed in 3D-printed structure Approvals for Nvidia and AMD AI chip exports to China stall under government bottleneck —  20% staff turnover… Espresso Lite 15 Review: An entry-level portable monitor with a splash of color Save a massive $700 on this 4K-ready HP gaming PC with a 9800X3D and RTX 5070 Ti, now just $2,499 — discounted HP Omen 35L pre-built powerhouse ships with 32GB DDR5 RAM and a 1TB SSD 'CopprLink' destroys every eGPU standard in new test, achieves near-native-level performance with an RTX 5090 — setup requires $2,300 worth of additional hardware Website backup crippled by 1.6MB Friends GIF that was replicated 246,173 times, breaking Linux's EXT4 filesystem limit — Jennifer Aniston's 'happy dance' animation ate up 377 gigabytes of data due to security policy Why we spent 50+ hours retesting Intel’s Core Ultra 270K Plus and 250K Plus Just $284.99 for 32GB of Team T-Create Classic DDR5-6000 RAM is the cheapest going right now — this double-dipping… Grab MSI’s RTX 5080 gaming laptop for just over $2,000 — offers fast 240 Hz QHD+ display, dual storage slots, and expandable DDR5 memory Lenovo hikes Legion Go 2 handheld gaming PC to almost $3,000 for 2 TB model — Handheld now costs more than AMD's Strix Halo devices despite relatively weaker Z2 Extreme chip Iran's forced nationwide internet blackout becomes second-longest on record as it passes 1,000 hours offline — possessing Starlink terminals punishable by death, country using 'military-grade jamming' against service Tiny 3-inch cube PCs bring a splash of color to the passive PC market with red, orange, green and blue options — Intel Twin Lake-powered Kubb Mini PCs start at $500 Veteran Microsoft engineer says original Task Manager was only 80KB so it could run smoothly on 90s computers — original utility used a smart technique to determine whether it was the only running instance Tech enthusiast gets Doom to run on a 40-year-old printer controller — ancient Agfa Compugraphic 9000PS came with a Motorola 68020 onboard for fast processing Keychron Q6 Ultra 8K Review: 660 hours of battery life at 8 KHz
Microsoft warns GPU mining malware is being spread to use...
Etiido Uko · 2026-05-29 · via Latest from Tom's Hardware
Crypto farm
(Image credit: Getty / Bloomberg)

Microsoft has uncovered an ongoing cryptojacking campaign that used SEO poisoning and, in some observed cases, AI chatbot-generated software recommendations to lure users into downloading GPU mining malware disguised as popular PC utilities. According to a detailed threat report published Tuesday by Microsoft Defender Experts and the Microsoft Defender Security Research Team, the operation specifically targeted users who likely own high-performance graphics cards, including gamers, hardware enthusiasts, AI users, and overclockers.

The campaign impersonated widely used utilities such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller (DDU), FurMark, K-Lite Codec Pack, and PDFgear. Victims searching for the software on traditional search engines — and, in some cases, via AI chatbot recommendations — were reportedly redirected to attacker-controlled download pages hosting malicious ZIP archives.

Microsoft says the attackers appear less interested in maximizing infection volume and more focused on compromising systems with powerful discrete GPUs suitable for profitable cryptocurrency mining. Once installed, the malware deployed persistent remote-access software using the legitimate ScreenConnect remote-management tool before silently loading GPU mining payloads such as lolMiner, gminer, and SRBMiner-MULTI.

The attack chain relied heavily on stealth techniques typically associated with more advanced malware operations. The downloaded archives bundled legitimate software installers alongside malicious DLLs that were automatically loaded through DLL sideloading. From there, the malware established six separate persistence mechanisms, added Microsoft Defender exclusions, checked for virtual machines and security-analysis tools, and used process hollowing to inject mining code into trusted Microsoft-signed .NET utilities such as MSBuild.exe, InstallUtil.exe, and RegAsm.exe.

Perhaps the most unusual aspect of the campaign, however, is Microsoft’s observation that some malicious domains may have surfaced through interactions with AI chatbots. According to the company, users requesting software download recommendations from large language model (LLM)-based assistants were, in some cases, presented with links to attacker-controlled domains embedded in generated responses. Microsoft stressed that the example was illustrative and “does not indicate a systemic issue with any specific AI service,” but noted that the activity appears consistent with emerging AI-assisted search-poisoning techniques.

According to Microsoft’s analysis, the operation has been active since at least March 2026 and involved more than 150 malicious domains masquerading as trusted utility-download portals. Many of the downloads were hosted on subdomains of gleeze.com, infrastructure linked to the Dynu dynamic DNS service, which has frequently been used in past phishing and malware campaigns.

The initial infection process itself was deceptively simple. Victims downloaded ZIP archives containing both the legitimate utility executable and a malicious DLL named autorun.dll. When the legitimate application launched, Windows automatically loaded the malicious DLL from the same directory via DLL sideloading — a long-standing Windows abuse technique that requires no software exploit and often produces no visible signs of compromise.

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

From there, the malware silently installed ScreenConnect, a legitimate enterprise remote-management platform also known as ConnectWise Control. Microsoft emphasized that ScreenConnect itself is not malicious, but rather is being abused by threat actors in the same way attackers increasingly misuse legitimate remote monitoring and management (RMM) tools to evade security scrutiny.

Once remote access was established, attackers deployed a binary called SimpleRunPE.exe, which Microsoft believes may partially derive from a publicly available GitHub proof-of-concept process hollowing project. The malware copied itself into hidden Windows directories as RuntimeHost.exe, created scheduled tasks and startup entries for persistence, and repeatedly re-added Microsoft Defender exclusions even if users or administrators attempted to remove them.

The malware also appeared engineered specifically to avoid detection by performance-conscious PC users. Microsoft says the miner monitored GPU utilization, system idle time, gaming activity, and streaming workloads, shutting down mining operations whenever heavy GPU activity was detected. In practice, this likely reduced obvious warning signs such as sudden frame-rate drops, overheating, or persistently loud GPU fans that might otherwise alert users to a compromise.

To further evade detection, the malware performed extensive anti-analysis checks before activating. The software scanned systems for virtual-machine artifacts, debugging tools, reverse-engineering platforms, packet analyzers, and forensic utilities, including Wireshark, ProcMon, x64dbg, dnSpy, IDA, and Ghidra. If any such tools were detected, the malware terminated itself.

Microsoft says the malware’s operators ultimately used the compromised systems to deploy one of several GPU-focused cryptocurrency miners, including lolMiner, gminer, and SRBMiner-MULTI. Rather than embedding the miners directly into the malware, the payload dynamically downloaded the most appropriate mining software after conducting extensive reconnaissance on the victim system, including GPU model, CPU specifications, installed antivirus software, memory configuration, and overall system activity.

The campaign highlights an alarming development in which attackers are now targeting not only search engines but also AI-assisted discovery systems. While traditional SEO poisoning has existed for years, the growing use of AI chatbots and LLM-powered assistants for software recommendations may be creating a new attack surface where malicious sites gain additional visibility through generated responses. Users need to be extra cautious, as even highly familiar utilities downloaded from seemingly convincing websites may carry hidden malware payloads, particularly when obtained through third-party mirrors or AI-provided links rather than official vendor pages.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Etiido Uko is a news contributor for Tom's Hardware covering the latest updates in big tech and the PC industry. He is a mechanical engineer and senior technical writer with over nine years of experience in documentation and reporting. He is deeply passionate about all things engineering and technology, and is an expert in gadgets, manufacturing, robotics, automotive, and aerospace.