From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
2026-05-28T02:52:19Z•dec774816ae28fc6501909ef84463a39b2c3b3cde7cd609abcbedbf93bdd07a3
AI chatbotGPU miningMicrosoft .NETSEO poisoningScreenConnectcampaigncoinminercryptojackingdrive-bymalicious sitespoisoned search resultsremote access
What happened
Microsoft details a widespread cryptojacking campaign that uses SEO-poisoned search results and malicious sites (sometimes surfaced by AI chatbots) to compromise high-performance Windows hosts and deploy GPU miners. The threat chain abuses ConnectWise/ScreenConnect remote‑access tooling and legitimate Microsoft .NET utilities to install and execute coin‑mining payloads, prioritizing systems with powerful GPUs. The campaign emphasizes drive‑by/SEO delivery, remote‑access abuse for persistence and control, and opportunistic targeting of high-value compute resources.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- dec774816ae28fc6501909ef84463a39b2c3b3cde7cd609abcbedbf93bdd07a3
- Enrichment time
- 2026-05-28T02:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.