Security researchers at Arctic Wolf have uncovered a new malware campaign, dubbed GPUGate, targeting users in Western Europe and distributed via Google Ads.

The campaign uses malicious GitHub Desktop installers to distribute its malicious payload. Attackers use trusted platforms to bypass traditional detection methods and entice users to download the malware.
“On August 19, 2025, a threat actor exploited the GitHub repository structure along with paid Google Ads placements to direct users to a malicious download hosted on a seemingly legitimate domain,” Arctic Wolf researchers reported. “By embedding a link in the ad, the attackers made the download appear to come from an official source, thereby bypassing users’ attention.”
See also: APT37 targets Windows with new Rust & Python Based Malware
The operators of the GPUGate malware also incorporated advanced evasion techniques, most notably a GPU-based decryption process, which ensures that the malware is only activated on systems with specific graphics hardware.
GPUGate: Malicious ads that appear as GitHub Desktop
Arctic Wolf’s Cybersecurity Operations Center (cSOC) spotted the malware being distributed via ads Google that directed users to compromised GitHub repositories. These ads were carefully crafted to appear legitimate, using commit-specific links that mimicked the genuine GitHub workflow. Once users clicked, they were redirected to fake domains hosting a malicious installer for GitHub Desktop.
This approach allowed attackers to exploit the trustworthiness of both GitHub and Google Ads, increasing the likelihood of a download. Researchers warned that the campaign aimed to infiltrate organizations by tricking IT staff– who typically have elevated network privileges. The goal was to trick the victim into downloading malware under the guise of installing GitHub Desktop. This could allow for credential theft, information extraction and even ransomware deployment.

“Once the malicious payload is executed by the user, the attacker gains administrator privileges, which allows them further lateral movement and establishment of persistence,” the researchers said.
See also: Hacker linked to ransomware operations Play, RansomHub & DragonForce
GPU-Gated decryption for detection evasion
The malware itself is delivered as a large Microsoft Software Installer (MSI) file, approximately 128 MB in size. It features a GPU-based decryption mechanism that keeps the payload encrypted unless it detects the presence of an actual GPU on the system. The researchers noted that this design allows GPUGate to remain dormant in virtual machines, automated analysis environments, or less powerful machines, making it extremely difficult for security researchers to analyze.
Once activated, the malware launches PowerShell with parameters designed to bypass Windows execution policies, while hiding its windows from users. In addition, persistence is achieved through a scheduled task that runs with elevated administrator privileges, allowing it to survive reboots and run across user sessions.

The campaign also targets macOS, distributing AMOS Stealer (also known as Atomic Stealer) via a custom installer that suits either x64 or ARM processors. This info-stealer, sold as malware-as-a-service, can extract a wide range of sensitive data, including keychain passwords, VPN profiles, browser credentials, instant messaging data, documents, and cryptocurrency wallets.
See also: From MostereRAT to ClickFix: New malware campaigns
The researchers noted that the inclusion of attacks across multiple platforms indicates the operator's goal of comprehensive, persistent access to various corporate environments.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“The malicious advertising and geo-targeting used are tailored to specifically target EU countries,” they added. “The targeted industries included workers in the Information Technology sector.”
For protection, Arctic Wolf recommends combining runtime inspection with sandboxing as well as increasing user awareness, as GPUGate's advanced evasion and convincing emulation make static defenses inadequate.
