HomeSecurityGPUGate malware: Exploiting GitHub and Google Ads for attacks

GPUGate malware: Exploiting GitHub and Google Ads for attacks

Security researchers at Arctic Wolf have uncovered a new malware campaign, dubbed GPUGate, targeting users in Western Europe and distributed via Google Ads.

GPUGate malware GitHub and Google Ads

The campaign uses malicious GitHub Desktop installers to distribute its malicious payload. Attackers use trusted platforms to bypass traditional detection methods and entice users to download the malware.

“On August 19, 2025, a threat actor exploited the GitHub repository structure along with paid Google Ads placements to direct users to a malicious download hosted on a seemingly legitimate domain,” Arctic Wolf researchers reported. “By embedding a link in the ad, the attackers made the download appear to come from an official source, thereby bypassing users’ attention.”

See also: APT37 targets Windows with new Rust & Python Based Malware

The operators of the GPUGate malware also incorporated advanced evasion techniques, most notably a GPU-based decryption process, which ensures that the malware is only activated on systems with specific graphics hardware.

GPUGate: Malicious ads that appear as GitHub Desktop

Arctic Wolf’s Cybersecurity Operations Center (cSOC) spotted the malware being distributed via ads Google that directed users to compromised GitHub repositories. These ads were carefully crafted to appear legitimate, using commit-specific links that mimicked the genuine GitHub workflow. Once users clicked, they were redirected to fake domains hosting a malicious installer for GitHub Desktop.

This approach allowed attackers to exploit the trustworthiness of both GitHub and Google Ads, increasing the likelihood of a download. Researchers warned that the campaign aimed to infiltrate organizations by tricking IT staff– who typically have elevated network privileges. The goal was to trick the victim into downloading malware under the guise of installing GitHub Desktop. This could allow for credential theft, information extraction and even ransomware deployment.

GPUGate malware: Exploiting GitHub and Google Ads for attacks

“Once the malicious payload is executed by the user, the attacker gains administrator privileges, which allows them further lateral movement and establishment of persistence,” the researchers said.

See also: Hacker linked to ransomware operations Play, RansomHub & DragonForce

GPU-Gated decryption for detection evasion

The malware itself is delivered as a large Microsoft Software Installer (MSI) file, approximately 128 MB in size. It features a GPU-based decryption mechanism that keeps the payload encrypted unless it detects the presence of an actual GPU on the system. The researchers noted that this design allows GPUGate to remain dormant in virtual machines, automated analysis environments, or less powerful machines, making it extremely difficult for security researchers to analyze.

Once activated, the malware launches PowerShell with parameters designed to bypass Windows execution policies, while hiding its windows from users. In addition, persistence is achieved through a scheduled task that runs with elevated administrator privileges, allowing it to survive reboots and run across user sessions.

GPUGate malware: Exploiting GitHub and Google Ads for attacks

The campaign also targets macOS, distributing AMOS Stealer (also known as Atomic Stealer) via a custom installer that suits either x64 or ARM processors. This info-stealer, sold as malware-as-a-service, can extract a wide range of sensitive data, including keychain passwords, VPN profiles, browser credentials, instant messaging data, documents, and cryptocurrency wallets.

See also: From MostereRAT to ClickFix: New malware campaigns

The researchers noted that the inclusion of attacks across multiple platforms indicates the operator's goal of comprehensive, persistent access to various corporate environments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“The malicious advertising and geo-targeting used are tailored to specifically target EU countries,” they added. “The targeted industries included workers in the Information Technology sector.”

For protection, Arctic Wolf recommends combining runtime inspection with sandboxing as well as increasing user awareness, as GPUGate's advanced evasion and convincing emulation make static defenses inadequate.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS