Microsoft Warns of New Mining Malware Targeting High-Performance PC Users

icon币界网
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
Cryptocurrency news emerged as Microsoft revealed a new mining malware targeting high-performance PC users. Attackers spread fake tools such as CrystalDiskInfo and FurMark through SEO poisoning and chatbot links. The malware conceals mining activities using DLL side-loading and process hollowing. Microsoft Defender now detects these threats. New token listings remain a key focus for traders amid growing security concerns.
CoinDesk reports:

Microsoft has revealed that a new wave of cryptocurrency mining attacks is targeting high-performance computer users, particularly hardware enthusiasts and PC gamers. Unlike previous attacks that sought large-scale infections, this campaign focuses on maximizing the computational output of individual devices, aiming to hijack high-end GPU resources for illegal mining.

Drive traffic using AI chatbots and search results

Microsoft Defender Experts say attackers are exploiting search engine optimization poisoning to embed malicious links in responses from large language model chatbots. Users seeking to download common system tools or hardware testing software are being redirected to lookalike phishing websites.

Software falsely disguised includes CrystalDiskInfo, HWMonitor, and FurMark. Users who download these receive not legitimate installers, but ZIP archives containing malicious files.

Hide the mining program using system tools

After the malicious file is executed, it silently launches on the system using DLL side-loading. The attack chain then deploys legitimate remote management tools like ScreenConnect to maintain persistent control over the compromised device.

Microsoft stated that the attackers also used techniques such as "process hollowing." A custom .NET payload would first launch a Windows tool signed by Microsoft, then inject mining code into its memory space to reduce the likelihood of detection.

Monitor GPU usage to avoid detection

This type of malware continuously monitors the host system, including GPU usage and user idle time. When system load increases or the user is actively using the computer, the mining program automatically stops to avoid detection through sudden performance drops.

Meanwhile, the malicious program repeatedly invokes Windows PowerShell to add relevant paths to antivirus exclusions, further extending its persistence.

Microsoft stated that Microsoft Defender Antivirus and Microsoft Defender for Endpoint are now able to detect and block threats associated with this attack.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.