The post Microsoft Warns of Sneaky Crypto Miner Threat Targeting High-End PC Users appeared on BitcoinEthereumNews.com. The AI and SEO attack chain Advanced evasionThe post Microsoft Warns of Sneaky Crypto Miner Threat Targeting High-End PC Users appeared on BitcoinEthereumNews.com. The AI and SEO attack chain Advanced evasion

Microsoft Warns of Sneaky Crypto Miner Threat Targeting High-End PC Users

For feedback or concerns regarding this content, please contact us at [email protected]
  • The AI and SEO attack chain
  • Advanced evasion 

Microsoft Threat Intelligence has found out about a sophisticated cryptojacking campaign that combines web exploitation and extremely sophisticated social engineering. 

This campaign deliberately targets hardware enthusiasts and PC gamers to hijack their high-performance GPU resources in order to illegally mine cryptocurrencies. 

Microsoft Defender Experts observed that threat actors are now poisoning AI chatbot results to trick unsuspecting users into downloading malware.

XRP Hits $1.4B in ETF Cash

Shiba Inu (SHIB) Sellers Exhausted, Dogecoin (DOGE) Zero Addition Question of Time, XRP Recovery Starts: Crypto Market Review

The AI and SEO attack chain

Cryptojacking campaigns tend to prioritize  infection volume over precision. 

However, this newly discovered campaign has been specifically designed to get as much yield per device as possible. 

Attackers lure targets using Search Engine Optimization (SEO) poisoning as well as  malicious links embedded in responses generated by Large Language Model (LLM) chatbots. 

card

Users who want to download some legitimate software are directed to lookalike domains.

Malicious sites masquerade as popular hardware monitoring and system utilities. 

Compromised download packages include CrystalDiskInfo, HWMonitor, FurMark, and so on. 

Advanced evasion 

After downloading the targeted software, they receive a ZIP archive with a malicious file. 

The system quietly launches the malware via DLL sideloading. 

From there, the malware deploys ScreenConnect, which is a legitimate commercial remote management tool. This makes it possible for nefarious actors to gain persistent access to the machine. 

The threat actors execute a technique known as process hollowing. 

A custom .NET payload called ⁠ launches a trusted, Microsoft-signed Windows utility and injects its mining code directly into the trusted utility’s memory space. 

The loader then downloads GPU-focused mining clients of the likes of gminer. 

The malware constantly monitors the host system to remain undetected:

It monitors active GPU usage and user idle time. The miner automatically terminates its activity so the victim doesn’t notice a sudden drop in PC performance.

The software repeatedly manipulates Windows PowerShell to add exclusion paths to antivirus settings. 

Microsoft confirmed that Microsoft Defender Antivirus and Microsoft Defender for Endpoint detect and block threats tied to this campaign. 

Source: https://u.today/microsoft-warns-of-sneaky-crypto-miner-threat-targeting-high-end-pc-users

Market Opportunity
Gensyn Logo
Gensyn Price(AI)
$0.02726
$0.02726$0.02726
-5.87%
USD
Gensyn (AI) Live Price Chart

AI Strategy: Powered 24/7

AI Strategy: Powered 24/7AI Strategy: Powered 24/7

Generate automated strategies using natural language

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Crypto Industry Flexes Political Muscle in Texas Primary Victories

Crypto Industry Flexes Political Muscle in Texas Primary Victories

Crypto PACs invested $10M+ in Texas primaries, ousting Rep. Al Green. Analysis of victories, spending patterns, and implications for digital asset policy. The post
Share
Blockonomi2026/05/28 14:42
CME Group to launch Solana and XRP futures options in October

CME Group to launch Solana and XRP futures options in October

The post CME Group to launch Solana and XRP futures options in October appeared on BitcoinEthereumNews.com. CME Group is preparing to launch options on SOL and XRP futures next month, giving traders new ways to manage exposure to the two assets.  The contracts are set to go live on October 13, pending regulatory approval, and will come in both standard and micro sizes with expiries offered daily, monthly and quarterly. The new listings mark a major step for CME, which first brought bitcoin futures to market in 2017 and added ether contracts in 2021. Solana and XRP futures have quickly gained traction since their debut earlier this year. CME says more than 540,000 Solana contracts (worth about $22.3 billion), and 370,000 XRP contracts (worth $16.2 billion), have already been traded. Both products hit record trading activity and open interest in August. Market makers including Cumberland and FalconX plan to support the new contracts, arguing that institutional investors want hedging tools beyond bitcoin and ether. CME’s move also highlights the growing demand for regulated ways to access a broader set of digital assets. The launch, which still needs the green light from regulators, follows the end of XRP’s years-long legal fight with the US Securities and Exchange Commission. A federal court ruling in 2023 found that institutional sales of XRP violated securities laws, but programmatic exchange sales did not. The case officially closed in August 2025 after Ripple agreed to pay a $125 million fine, removing one of the biggest uncertainties hanging over the token. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/cme-group-solana-xrp-futures
Share
BitcoinEthereumNews2025/09/17 23:55
Luxor Ships Commander Software to Optimize Bitcoin Mining Fleet Profitability – News Bytes Bitcoin News

Luxor Ships Commander Software to Optimize Bitcoin Mining Fleet Profitability – News Bytes Bitcoin News

The post Luxor Ships Commander Software to Optimize Bitcoin Mining Fleet Profitability – News Bytes Bitcoin News appeared on BitcoinEthereumNews.com. Seattle-based
Share
BitcoinEthereumNews2026/04/02 18:41

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!