The GPU mining malware campaign reported by Microsoft is a clear reminder that attackers are now manipulating both search engines and AI chatbot recommendations to push malicious downloads. Users searching for common utilities like CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear were redirected to fake download pages that delivered malware instead of legitimate tools.
This campaign is especially concerning because it targets high-performance systems with powerful GPUs, making each compromised machine more valuable for cryptocurrency mining. The attackers used SEO poisoning to boost malicious links in search results, and some users were reportedly directed to attacker-controlled domains through AI chatbot-generated recommendations. So yes, even “I asked an AI where to download software” has now entered the threat model, because apparently the internet was not already exhausting enough.
Once infected, the malware deployed ScreenConnect for persistent remote access, used DLL side-loading, added Microsoft Defender exclusions, checked for virtual machines and analysis tools, and then downloaded GPU mining tools such as gminer, lolMiner, and SRBMiner-MULTI. This is not just about slower computers or higher electricity bills. Remote access can later be abused for credential theft, data exfiltration, lateral movement, or additional malware deployment.
Users and organizations should download software only from official vendor websites, avoid sponsored or unfamiliar download links, and verify domains before installing utilities. Security teams should monitor for unusual ScreenConnect installations, suspicious PowerShell activity, Defender exclusions, process hollowing behavior, and unexpected GPU usage. DNS filtering, web filtering, endpoint monitoring, and user awareness all matter here.
The broader lesson is simple: attackers follow user behavior. As people increasingly rely on AI tools and search engines to find software, criminals are poisoning those discovery paths. A download link is not safe just because it appears in search results or comes from an AI-generated answer. Trust still needs verification, annoying as that is for everyone trying to install a utility in peace.
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. [...]
Source: GPU mining malware spreads via SEO poisoning, AI chatbots via Bleeping Computer — published 27 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.