“GPUGate” Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload
A malware campaign known as "GPUGate" exploits Google Ads and GitHub's repository structure to deceive users into downloading harmful software.
A malware campaign known as "GPUGate" exploits Google Ads and GitHub's repository structure to deceive users into downloading harmful software.
The Arctic Wolf Cybersecurity Operations Center has reported that the GPUGate attack employs a novel technique to evade security analysis by utilizing a computer's Graphics Processing Unit (GPU).
The campaign is attributed to a Russian-speaking threat actor and targets IT professionals in Western Europe.
The attack begins with malicious advertising, where attackers place a sponsored ad at the top of Google search results for terms such as "GitHub Desktop." This ad directs users to what appears to be a legitimate GitHub page.
However, the link leads to a manipulated "commit" page within a repository. This page looks authentic, retaining the repository's name and metadata, but contains altered download links pointing to an attacker-controlled domain.
A malware campaign known as "GPUGate" exploits Google Ads and GitHub's repository structure to deceive users into downloading harmful software.
This strategy leverages user trust in both Google and GitHub to deliver the malicious payload.
GPUGate is notable for its unique evasion method. The initial installer is a large 128 MB file, designed to bypass security sandboxes that often impose file size limits.
Its most innovative feature is a GPU-gated decryption routine. The malware decrypts its payload only if it detects a real, physical GPU with a device name longer than ten characters. This is a deliberate tactic to avoid analysis, as virtual machines and sandboxes typically have generic, short GPU names or none at all. On such systems, the payload remains encrypted and inactive.
The primary aim of this campaign is to gain initial access to organizational networks for malicious activities, including credential theft, data exfiltration, and ransomware deployment.
By targeting developers and IT workers, individuals likely to seek tools like GitHub Desktop, the attackers aim for victims with elevated network privileges.
Once executed, the malware uses a PowerShell script to obtain administrative rights, create scheduled tasks for persistence, and add exclusions to Windows Defender to avoid detection. The campaign has been active since at least December 2024 and presents an evolving and significant threat.
Based on reporting by Cyber Security News.
