Cyber Security News

“GPUGate” Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload

A sophisticated malware campaign, dubbed “GPUGate,” abuses Google Ads and GitHub’s repository structure to trick users into downloading malicious software.

The Arctic Wolf Cybersecurity Operations Center, the attack chain uses a novel technique to evade security analysis by leveraging a computer’s Graphics Processing Unit (GPU).

The campaign appears to be the work of a Russian-speaking threat actor and is actively targeting IT professionals in Western Europe.

The attack begins with malicious advertising, where attackers place a sponsored ad at the top of Google search results for terms like “GitHub Desktop.” This ad directs users to what appears to be a legitimate GitHub page.

Google search results for GitHub Desktop

In reality, the link leads to a specific, manipulated “commit” page within a repository. This page looks authentic, retaining the repository’s name and metadata, but contains altered download links that point to an attacker-controlled domain.

This “trust bridge” exploits the user’s confidence in both Google and GitHub to deliver the malicious payload.

What makes GPUGate particularly notable is its unique evasion method. The initial installer is a large 128 MB file, designed to bypass security sandboxes that often have file size limits.

weaponized GitHub Desktop

Its most innovative feature is a GPU-gated decryption routine. The malware will only decrypt its malicious payload if it detects a real, physical GPU with a device name longer than ten characters, Arctic Wolf said.

This is a deliberate tactic to thwart analysis, as the virtual machines and sandboxes used by security researchers often have generic, short GPU names or no GPU at all. On such systems, the payload remains encrypted and inert.

The primary goal of this campaign is to gain initial access to organizational networks for malicious activities, including credential theft, data exfiltration, and ransomware deployment.

By targeting developers and IT workers, individuals likely to seek tools like GitHub Desktop, the attackers aim for victims with elevated network privileges.

Once executed, the malware uses a PowerShell script to gain administrative rights, create scheduled tasks for persistence, and add exclusions to Windows Defender to avoid detection. The campaign has been active since at least December 2024 and represents an evolving and significant threat.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago