PULSE NAME
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
WHITE AlienVault 2026-05-27 Modified: 2026-05-27
27
IOCs
MEDIUM VOLUME
Microsoft Defender Experts identified an active cryptojacking campaign leveraging AI-assisted delivery mechanisms alongside traditional SEO poisoning. Attackers create fake download sites impersonating trusted utilities like CrystalDiskInfo, HWMonitor, and FurMark, targeting users with high-performance GPUs. Victims download ZIP archives containing legitimate executables bundled with malicious DLLs that establish persistence via ScreenConnect remote access tools. The operation employs sophisticated techniques including DLL sideloading, process hollowing into Microsoft-signed .NET binaries, and comprehensive defense evasion. Beyond cryptocurrency mining, the campaign establishes persistent remote access that could enable data theft, lateral movement, or ransomware deployment. The threat actors deliberately target PC enthusiasts and hardware-focused users most likely to own discrete GPUs suitable for profitable mining operations.
Indicators of Compromise (1 / 27 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 hostname URL
TYPEINDICATORDESCRIPTIONCREATED
URL http://minemine.gleeze.com:8443/ws 2026-05-27