Affected Systems
Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.
Exploitation Status
Active campaign disclosed by Microsoft. Threat actors are actively using SEO poisoning and AI chatbot manipulation to distribute malicious sites leading to ScreenConnect abuse and cryptomining payloads.
Business Impact
Compromised systems experience degraded performance due to unauthorized GPU mining activity. Organizations face increased electricity costs, potential hardware damage from sustained GPU load, and risk of persistent remote access via ScreenConnect. Legitimate ScreenConnect deployments may be abused if credentials are compromised. No direct data exfiltration reported, but remote access capability enables lateral movement and further compromise.
Urgency
🟠Within 24 hours
Recommended Actions
- Audit all ScreenConnect installations and active sessions; revoke unauthorized or suspicious remote access connections immediately
- Monitor network traffic for connections to known cryptomining pools and block at firewall; inspect GPU utilization spikes on workstations and servers
- Review web proxy and DNS logs for SEO-poisoned domains and AI chatbot referrals; block identified malicious sites
- Inspect use of Microsoft .NET utilities (e.g., MSBuild.exe, InstallUtil.exe, RegAsm.exe) via EDR or Sysmon Event ID 1; investigate unexpected executions
- Harden ScreenConnect deployments with MFA, restrict access by IP allowlist, and ensure software is updated to latest version
