PULSE NAME
GPUGate Malware: Malicious GitHub Desktop Implants Use Hardware-Specific Decryption, Abuse Google Ads to Target Western Europe
WHITE AlienVault 2025-09-08 Modified: 2025-10-08
39
IOCs
MEDIUM VOLUME
A sophisticated malware campaign dubbed 'GPUGate' has been uncovered, targeting Western European IT professionals through malicious Google Ads mimicking GitHub Desktop. The attack leverages GitHub's repository structure and a GPU-gated decryption mechanism to evade analysis. The malware, a 128 MB MSI file, contains over 100 dummy executables and employs OpenCL for hardware-specific decryption, ensuring execution only on systems with real GPUs. The campaign aims to gain initial access for credential theft and potential ransomware deployment. It demonstrates native Russian language proficiency and deep anti-analysis knowledge. The attackers' selective approach and GPU-based evasion technique present significant challenges for traditional malware analysis methods.
Indicators of Compromise (6 / 39 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1e0b2ef7208c86e2e66a2945b0716738 2025-09-08
FileHash-MD5 56b76ecf127d6fd8a5c0c599cd732842 2025-09-08
FileHash-MD5 935026f24588d35661d53f8e34993b54 2025-09-08
FileHash-MD5 9d283e2d36a649a499cac543cd27d5a5 2025-09-08
FileHash-MD5 a34392f357ae602e3f1d0822fe77f8d1 2025-09-08
FileHash-MD5 b3e5b0ddab44f789dd51e8187edca0b7 2025-09-08