{"id":6727,"date":"2025-09-07T10:03:47","date_gmt":"2025-09-07T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/07\/gpugate-malware-abuses-google-ads-and-github-to-deliver-advanced-malware-payload\/"},"modified":"2025-09-07T10:03:47","modified_gmt":"2025-09-07T10:03:47","slug":"gpugate-malware-abuses-google-ads-and-github-to-deliver-advanced-malware-payload","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/07\/gpugate-malware-abuses-google-ads-and-github-to-deliver-advanced-malware-payload\/","title":{"rendered":"\u201cGPUGate\u201d Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload"},"content":{"rendered":"<p>    \u201cGPUGate\u201d Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign, dubbed \u201cGPUGate,\u201d abuses Google Ads and GitHub\u2019s repository structure to trick users into downloading malicious software.<\/p>\n<p>The Arctic Wolf Cybersecurity Operations Center, the attack chain uses a novel technique to evade security analysis by leveraging a computer\u2019s Graphics Processing Unit (GPU).<\/p>\n<p>The campaign appears to be the work of a Russian-speaking threat actor and is actively targeting IT professionals in Western Europe.<\/p>\n<p>The attack begins with malicious advertising, where attackers place a sponsored ad at the top of Google search results for terms like \u201cGitHub Desktop.\u201d This ad directs users to what appears to be a legitimate GitHub page.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" height=\"981\" width=\"1024\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiFLIYrfkvfKwd0jSPzn9IJaTv9LUsVxJlLMUJB3dvMldoGODDG79YCv3m-xTc-ZsVG7ChVRJVGez0RvbNmS758HpxmGy5koPkGqVp33-HW0MZCXhNPtu5x5I7DNTha7atsXOjTvxEERg3Cu2Z8jO4MJsBsxo2lD6DE4MjeszV0RD2pCj_4vVkhOXdzBIyK\/w640-h614\/gpugate-fig01-1024x981.webp?resize=1024%2C981&#038;ssl=1\" alt=\"Google search results for GitHub Desktop\"><figcaption class=\"wp-element-caption\">Google search results for GitHub Desktop<\/figcaption><\/figure>\n<\/div>\n<p>In reality, the link leads to a specific, manipulated \u201ccommit\u201d page within a repository. This page looks authentic, retaining the repository\u2019s name and metadata, but contains altered download links that point to an attacker-controlled domain.<\/p>\n<p>This \u201ctrust bridge\u201d exploits the user\u2019s confidence in both Google and GitHub to deliver the malicious payload.<\/p>\n<p>What makes GPUGate particularly notable is its unique evasion method. The initial installer is a large 128 MB file, designed to bypass security <a href=\"https:\/\/cybersecuritynews.com\/3-soc-metrics-improved-with-sandbox-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">sandboxes<\/a> that often have file size limits.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjUFE7oi7cfstODD6nhyV5Mf89m-mLCETlOVjTPCDk9fKormVBZArtTqHIL8xg2J2VcLTv19Jp1OkdkfsMW4U-woegOCrDZI3nyIGkosZgF4hREHLL2Drp7QjvAyRroCIxfJejcRjhwxUzWCDiNUcEObZdl9uHgnM8xx59X7u1FWiWhl339DLcTGHMrNy5i\/w640-h556\/gpugate-fig03.webp?ssl=1\" alt=\"weaponized GitHub Desktop\"><figcaption class=\"wp-element-caption\">weaponized GitHub Desktop<\/figcaption><\/figure>\n<\/div>\n<p>Its most innovative feature is a GPU-gated decryption routine. The malware will only decrypt its malicious payload if it detects a real, physical GPU with a device name longer than ten characters, Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/gpugate-malware-malicious-github-desktop-implants-use-hardware-specific-decryption-abuse-google-ads-target-western-europe\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">said<\/a>.<\/p>\n<p>This is a deliberate tactic to thwart analysis, as the virtual machines and sandboxes used by security researchers often have generic, short GPU names or no GPU at all. On such systems, the payload remains encrypted and inert.<\/p>\n<p>The primary goal of this campaign is to gain initial access to organizational networks for malicious activities, including <a href=\"https:\/\/cybersecuritynews.com\/tag\/credential-theft\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a>, data exfiltration, and ransomware deployment.<\/p>\n<p>By targeting developers and IT workers, individuals likely to seek tools like GitHub Desktop, the attackers aim for victims with elevated network privileges.<\/p>\n<p>Once executed, the malware uses a <a href=\"https:\/\/cybersecuritynews.com\/onedrive-phishing-powershell-trick\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell script<\/a> to gain administrative rights, create scheduled tasks for persistence, and add exclusions to Windows Defender to avoid detection. The campaign has been active since at least December 2024 and represents an evolving and significant threat.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gpugate-abuses-google-ads\/\">\u201cGPUGate\u201d Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gpugate-abuses-google-ads\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cGPUGate\u201d Malware Abuses Google Ads and GitHub to Deliver Advanced Malware Payload A sophisticated malware campaign, dubbed \u201cGPUGate,\u201d abuses Google Ads and GitHub\u2019s repository structure to trick users into downloading malicious software. The Arctic Wolf Cybersecurity Operations Center, the attack chain uses a novel technique to evade security analysis by leveraging a computer\u2019s Graphics Processing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258,649],"tags":[130],"class_list":["post-6727","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6727"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6727"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6727\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}