Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

An active cryptojacking campaign, documented by Microsoft Defender Experts on May 26, 2026, targets PC enthusiasts and hardware hobbyists by poisoning search engine results and manipulating AI chatbot responses to distribute trojanized versions of popular utilities such as CrystalDiskInfo, HWMonitor, FurMark, and PDFgear. Once installed, the malware silently deploys ScreenConnect (ConnectWise Control) for persistent remote access and injects a GPU cryptocurrency miner into legitimate Windows processes to evade detection. The ScreenConnect backdoor extends the risk far beyond resource theft, creating an established foothold for lateral movement, credential harvesting, data exfiltration, and ransomware staging across any endpoint where the software was executed.

Author

Tech Jacks Solutions