PULSE NAME
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
WHITE AlienVault 2026-05-27 Modified: 2026-05-27
27
IOCs
MEDIUM VOLUME
Microsoft Defender Experts identified an active cryptojacking campaign leveraging AI-assisted delivery mechanisms alongside traditional SEO poisoning. Attackers create fake download sites impersonating trusted utilities like CrystalDiskInfo, HWMonitor, and FurMark, targeting users with high-performance GPUs. Victims download ZIP archives containing legitimate executables bundled with malicious DLLs that establish persistence via ScreenConnect remote access tools. The operation employs sophisticated techniques including DLL sideloading, process hollowing into Microsoft-signed .NET binaries, and comprehensive defense evasion. Beyond cryptocurrency mining, the campaign establishes persistent remote access that could enable data theft, lateral movement, or ransomware deployment. The threat actors deliberately target PC enthusiasts and hardware-focused users most likely to own discrete GPUs suitable for profitable mining operations.
Indicators of Compromise (5 / 27 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 hostname URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 017830597704acd90fb171f3025bc6f28745da57 2026-05-27
FileHash-SHA1 62d5e9ed6c1444469e4b89f3ca6c2047a5e8eb98 2026-05-27
FileHash-SHA1 bbeaac7ef00268bd5cc583e26624e760085581dc 2026-05-27
FileHash-SHA1 c27a1688fa5a4ec9497da0fc9bd88c8b362234c5 2026-05-27
FileHash-SHA1 f9ea4f4b636614226579ac6cbfc8abe21539a8da 2026-05-27