From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities

2026-05-28T02:52:19Zdec774816ae28fc6501909ef84463a39b2c3b3cde7cd609abcbedbf93bdd07a3
AI chatbotGPU miningMicrosoft .NETSEO poisoningScreenConnectcampaigncoinminercryptojackingdrive-bymalicious sitespoisoned search resultsremote access

What happened

Microsoft details a widespread cryptojacking campaign that uses SEO-poisoned search results and malicious sites (sometimes surfaced by AI chatbots) to compromise high-performance Windows hosts and deploy GPU miners. The threat chain abuses ConnectWise/ScreenConnect remote‑access tooling and legitimate Microsoft .NET utilities to install and execute coin‑mining payloads, prioritizing systems with powerful GPUs. The campaign emphasizes drive‑by/SEO delivery, remote‑access abuse for persistence and control, and opportunistic targeting of high-value compute resources.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
dec774816ae28fc6501909ef84463a39b2c3b3cde7cd609abcbedbf93bdd07a3
Enrichment time
2026-05-28T02:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities · Baitaphish