From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities

2026-05-27T14:52:18Zf360f3b7440f9c0d2d4664fd2b690a9ff1119b3c5e60575bd8e1d9a1d0841f30
AI chatbotsCI/CD compromiseClarityConfluenceF5 BIG-IPFox TempestGPU miningKerberos relayMicrosoft .NETMini Shai HuludRAMPARTSEO poisoningScreenConnectStorm-2949cloud breachcredential theftcryptojackingidentity compromiselateral movementmalware-signing-as-a-servicenpm supply chainopen-source security toolsransomware distributionsecurity updatesworkforce identity

What happened

Microsoft Security Blog published multiple threat reports and updates. Notable incidents include a cryptojacking campaign that uses SEO poisoning, malicious sites amplified via AI chatbots, ScreenConnect, and Microsoft .NET utilities to deploy GPU-mining payloads on high-performance PCs; a multi-stage Linux intrusion that started from an exposed F5 BIG-IP appliance and pivoted to Confluence for credential theft, Kerberos relay attempts, and lateral movement; compromised @antv npm packages (Mini Shai Hulud) that steal CI/CD credentials from Linux automation environments (targeting GitHub, AWS,K

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
f360f3b7440f9c0d2d4664fd2b690a9ff1119b3c5e60575bd8e1d9a1d0841f30
Enrichment time
2026-05-27T14:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.