Skip to main content

GPUs could become Trojan horses for future cyberattacks

NVIDIA CEO Jensen Huang at GTC
Nvidia

The graphics card inside your computer is a powerful tool for gaming and creative work, but it can also potentially serve as a Trojan horse for malware. Cybercriminals are finding ways to exploit graphics cards and their VRAM to inject malicious code into your system. The approach is claimed to have worked during a proof-of-concept hack on both discrete and integrated GPUs from AMD, Intel, and Nvidia.

Because antivirus software today cannot scan the graphics card’s own video RAM, known as VRAM, hackers are now targeting GPUs to carry out their dirty work. On the other hand, conventional methods used today that target the system’s main memory would trigger the antivirus software.

According to Bleeping Computer, a brief description of the hack was posted on a hacker forum, where one seller was trying to sell his proof-of-concept method to exploit the VRAM on GPUs. The seller stated that the method worked on Intel’s integrated UHD 620 and 630 graphics, as well as discrete solutions including the AMD Radeon RX 5700 and Nvidia GeForce GTX 1650. It’s unclear if the attack would also work on other GPUs, like the recent Radeon RX 6000 series from AMD and the Geforce RTX 3000 series from Nvidia, both of which have seen high demand and short supply.

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

The listing to sell the proof of concept was posted on August 8, and the method of exploit was sold on August 25, though details about the transactions were not revealed. It’s unknown who purchased the hack or how much was paid.

Though specifics about the exploit that was sold to other hackers are not known, cybersecurity researchers at VX-Underground stated that the method allowed the code to be run by the GPU and in the VRAM rather than by the CPU. The researchers said that they will be demonstrating the method of exploit soon.

While targeting the GPU for cyberattacks may be different from traditional hacks today, the method isn’t entirely novel. This latest exploit follows a similar proof of concept from six years ago known as JellyFish.

With the JellyFish proof of concept, researchers exploited the graphics card with a GPU-based keylogger. The seller of this latest GPU-based hack denied similarities behind his method and JellyFish, Bleeping Computer stated.

Given that your GPU could potentially be exploited by a malicious actor in the future to hide and execute malware, PC owners, gamers, and creators should stay vigilant of suspicious emails, links, files, and downloads. This is especially pertinent given that malware that sits in VRAM can be undetectable by antivirus software.

Editors' Recommendations

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
5 GPUs you should buy instead of the RTX 4070
RTX 4070 logo on a graphics card.

Nvidia's RTX 4070 is one of the best graphics cards you can buy, make no mistake about that. Some recent price drops, combined with excellent 1440p performance and features like DLSS 3.5, make it the go-to GPU for a high-end gaming experience in 2024. There are several other GPUs to keep in mind around this price, however.

The market around for graphics cards that cost $500 to $600 is hotly contested among AMD and Nvidia, and there are some other excellent options to keep in mind when shopping for a new GPU. Here are five GPUs to consider if you're in the market for the RTX 4070.
Nvidia RTX 4070 Super

Read more
How 8GB VRAM GPUs could be made viable again
Screenshot of full ray tracing in Cyberpunk 2077.

Perhaps there is still some hope for GPUs with low VRAM. According to a new patent published by Microsoft, the company worked out a method that could make ray tracing and path tracing more viable in terms of how much video memory (VRAM) they use. As of right now, without using upscaling techniques, seamless ray tracing requires the use of one of the best graphics cards—but this might finally change if this new method works out as planned.

This new patent, first spotted by Tom's Hardware, describes how Microsoft hopes to reduce the impact of ray tracing on GPU memory. It addresses the level of detail (LOD) philosophy, which is already something that's used in games but not in relation to ray tracing, and plans to use LOD to adjust ray tracing quality dynamically, thus lowering the load that the GPU -- particularly its memory -- has to bear.

Read more
AMD needs to fix this one problem with its next-gen GPUs
The RX 7800 XT graphics card with the ReSpec logo.

AMD's current-gen graphics cards have been a revelation. Last generation, AMD was able to hit performance parity with Nvidia while sacrificing ray tracing performance. This generation, AMD is maintaining parity while getting closer in ray tracing, as showcased by GPUs like the RX 7900 GRE. But the next frontier of gaming is rapidly approaching, and AMD's current options aren't up to the task right now.

I'm talking about path tracing. Nvidia calls it "full ray tracing," and it's a lighting technique that can take gaming visuals to the next level. Path tracing is only available in a small list of titles right now, but with frame generation and upscaling tools better than they've ever been, it won't be long before we see these destination gaming experiences everywhere.
Player two in path tracing

Read more