Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots.
www.microsoft.com
"The operator runs a coordinated SEO poisoning operation that simultaneously masquerades as a broad portfolio of trusted utility brands, where each one serves the same downstream payload chain.
The campaign abuses multiple trusted brands, including: CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear. The selection of these brands is deliberate. Each application is favored by PC enthusiasts and hardware-focused users, precisely the audience most likely to own a high-performance discrete GPU, the hardware that makes GPU cryptocurrency mining economically viable."
In this example, CIS can be compromised, and RemoteAdmin tool is installed. Then a connection to C2 server is established to download/execute the EXE malware (SimpleRunPE.exe = PE loader). The hash of this EXE loader is unknown (so far) to Comodo Valkyrie, so the file is Unrecognized to CIS and contained. As in the previous example, the attack can be mitigated by CIS before the final payload is executed.