Hidden GPU Mining Behind False Search and IA Responses

Author: Published 4 min de lectura 183 reading

The images in this article were generated with artificial intelligence. How we publish

A new organized effort to SEO poisoning and manipulation of recommendations from artificial intelligence assistants is being used by malicious actors to distribute cryptominery malware to teams with powerful GPUs. Microsoft researchers describe how false download pages for legitimate utilities - common programs between players, hardware enthusiasts and system administrators - are artificially positioned in search results and, in some cases, appear within responses generated by chatbots, redirecting users to ZIP files that combine legitimate binaries with malicious DLs. More technical details are available in Microsoft's report: Microsoft Security Blog.

The technique that analysts describe is doubly dangerous: first, take advantage of user confidence in known profit names (e.g. Crystal DiskInfo, HWMonitor, FurMark) to induce download; second, use side-loading from DLL and process holding to run the malicious code within binaries signed by Microsoft, reducing the probability of detection. The attacker also installs the legitimate ScreenConnect remote access tool to maintain persistence and deploy other components, and finally download GPU mining engines such as gminer, lolMiner or SRBMiner-MULTI to squeeze the graphic capacity of the machine.

Hidden GPU Mining Behind False Search and IA Responses
Image generated with IA.

The campaign is not a simple mass spam: it is calculated for maximise the performance of mining per compromised device, attacking teams with powerful graphics cards rather than infecting large volumes of PCs with weak CPUs. The adversaries also try to evade analysis by checking virtualized environments and excluding forensic tool processes from the checks, and even manipulate Microsoft Defender configurations to add exclusions and hide their trail. The domain involved in at least one family of suspicious files, gleeze.com, had already been pointed out by previous investigations: Malharebytes sobre gleeze [.] com.

What are the implications for users and organizations? In addition to resource consumption and impact on the electrical bill, an infection of this kind opens the door to more serious commitments: ScreenConnect or any remote access tool installed in a clandestine way can allow attackers to run ransomware, exfilter data or pivote laterally within a network. For data centres, 3D design workstations or research laboratories that depend on GPUs, the involvement can be especially costly and disruptive.

In terms of detection, there are signs that should be monitored: sudden growth in the use of GPU, processes signed by Microsoft that act as containers (suspected process holding), unusual activity of msiexec.exe linked to unauthorized installations, the presence of ScreenConnect or files that manifest themselves in self-start locations and entries in the Defend exclusions list that the computer has not consciously added. The analysis of the code also showed a component similar to a public implementation of runPE; those who want to review this technique can consult open resources such as this technical repository: Simple-RunPE (GitHub).

Hidden GPU Mining Behind False Search and IA Responses
Image generated with IA.

The concrete and priority actions we recommend to implement immediately are clear: first, do not blindly rely on links generated by search engines or IA assistants; always check the official developer sites and the digital signatures / hashes of the installers. Second, restrict installation permits to non-administrative users and apply white application lists (AppLocker / WDAC) in critical environments to prevent the execution of unauthorized binaries. Third, for critical GPUs equipment, implement specific alerts for abnormal use of GPU and outgoing traffic to mining tools, and block domains and subdomains identified as malicious in the proxy or firewall.

For defenders and administrators, additional controls should be added: audit the list of antivirus exclusions, monitor parent processes and invocation chains to detect hollowing, block msiexec.exe and other installation utilities so as not to be invoked by unexpected processes, and apply network segmentation so that any unexpected remote access does not allow lateral movement. Microsoft publishes commitment indicators and associated detection rules that can be consumed for EDR / IDS settings; see the report and apply these IOC in your environment: Microsoft report.

Finally, if you suspect that a team was engaged, disconnect it from the network and preserve evidence: to flip autostart processes and lists, to review installed services and registration keys, and to check the presence of ScreenConnect or executable with suplanted names (e.g. vlc.exe on unexpected routes). Notify the security team and consider a clean reinstallation if persistence is complex. The combination of social engineering through search and recommendations generated by IA shows that digital hygiene and source validation remain the best defence; distrust shortcuts and confirm with official sources.

Coverage

Related

More news on the same subject.