semiconductor / news / / Help Net Security
The campaign impersonates legitimate software tools such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller (DDU), FurMark, K-Lite Codec Pack, and PDFgear.
Cybercriminals use AI chatbot interactions to provide malicious links, not just poisoned search results.
KEY POINTS
- Over 150 campaign-linked domains were identified since March 2026 distributing trojanized software utilities.
- Malware deploys ScreenConnect for persistent remote access, enabling further data theft or ransomware attacks.
- Attackers target users likely to own high-performance GPUs suitable for cryptocurrency mining, not mass infections.
- Malware monitors for forensic tools and halts mining activity if such software is detected.
COMPANIES
Summarized by Newsio from Help Net Security. How we summarize →