Skip to main content

That disruptive crypto mining tool has a dark secret

A tool that claimed to remove all the existing mining limits on several popular Nvidia GPUs has proven to be malware instead.

The Nvidia RTX LHR v2 Unlocker by Sergey was revealed as a program that would modify the BIOS of Nvidia RTX 30-series graphics cards in order to unlock full mining performance. However, following an early launch, it has now been discovered that the creator planned to spread dangerous malware to users.

A cryptocurrency mining rig from a computer graphic card.
A cryptocurrency miner attached to a laptop Getty Images

Initially due for a public beta version release next week on February 28, the tool was released yesterday on the developer’s GitHub page, which has since been removed. According to PCGamer, upon downloading and running the ‘LHRUnlocker Install.msi’ file, powershell.exe is deployed, a Windows service infected with malware. Tom’s Hardware also reports that a malware scan via Joe Sandbox confirms the tool attempts to block Windows Defender from detecting it.

As reported by PCMag, Russian data scientist Mikhail Stepanov offered some further insight into the malicious program that was posing as an Ethereum mining unlocker. The installer itself includes a Nvidia GeForce driver file that 18 different antivirus scans recognize as malware.

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

Stepanov, a cryptocurrency miner himself, attempted to unpack the installer and run it via a virtual machine. As opposed to a tool that could have once again changed the landscape of the GPU market, he found that the installer extracts a harmful driver file from a server located at “drivers.sergeydev[.]com.”

While the exact motive behind the developer’s decision to spread malware remains unclear, Stepanov provided a clue as to what it may have been. “This is a common Trojan,” Stepanov told PCMag. “Most likely they wanted to build a botnet.”

Botnets have become an effective method in installing crypto mining malware on systems, so it’s not farfetched to assume that Sergey may have been planning to generate crypto profits by taking advantage of users who downloaded his file. Of course, it makes perfect sense that Sergey wanted to build a crypto mining botnet. He could have been due to receive a huge financial windfall by mining on thousands or tens of thousands of computers without lifting a finger himself. He would also not have to pay for the electricity costs associated with such activity.

The timing of the Nvidia RTX LHR v2 Unlocker’s announcement was suspicious in and of itself when considering the current state of the cryptocurrency market. With prices falling across the board for some of the most popular coins such as Bitcoin and ETH, the whole crypto space is currently in free fall. Why would someone start mining now when it would take well over a year to even recoup the cost of just the Nvidia GPU?

Tom’s Hardware points out that cryptocurrency mining profitability has been continuing to decrease as of late. A full-speed RTX 3080 Ti will make a miner $3.50 per day. When factoring in the price tag of $1,700 for the GPU itself, it would take nearly 500 days to just break even.

Editors' Recommendations

Zak Islam
Former Digital Trends Contributor
Zak Islam was a freelance writer at Digital Trends covering the latest news in the technology world, particularly the…
CableMod’s adapters damaged up to $74K worth of Nvidia GPUs
Melted 12VHPWR connector made by CableMod for the RTX 4090.

CableMod's adapters were meant to fix the problem of melting connectors on Nvidia's top GPU, the RTX 4090, but it appears that things didn't go as planned. The Consumer Product Safety Commission has posted a notice that the CableMod 12VHPWR angled adapters are being recalled due to fire and burn hazards. More than 25,300 adapters are to be returned, and the affected customers are eligible for a full refund.

The connectors on the RTX 4090 have been melting ever since the GPU hit the shelves in late 2022, and so far, the only fix seems to lie in careful installation and picking the right PC case that can accommodate this monstrous card. CableMod's angled adapters showed a lot of promise, at least initially. Seeing as bending the cable can contribute to the overheating, an angled adapter should have been just the fix -- but unfortunately, the melting continued, even with the use of CableMod's solution.

Read more
Nvidia just fixed a major issue with its GPUs
The Nvidia RTX 4080 Super on a pink background.

If you've been unhappy with the performance of your graphics card lately, you might want to check out Nvidia's latest beta driver. This is a hotfix driver, which is pretty unusual for Nvidia, but it can be helpful if you've been dealing with micro-stuttering, both in games and on the desktop. The update addresses four issues in total, but to get it, you'll have to dig a little deeper than the standard path of updating your drivers.

Nvidia typically bundles bug fixes with its usual Game Ready drivers, as urgent hotfixes tend to be few and far between. However, this time, Nvidia chose not to wait any longer and pushed four updates for its GPU range. The new driver version, 551.46, may fix annoying stuttering issues.

Read more
The best GPUs if you’re upgrading from a GTX 1650
RTX 3050 graphics card among PC accessories.

Nvidia's GTX 1650 is nothing short of a legendary graphics card. The humble, budget-focused GPU has achieved a massive status among PC gamers, sitting at the top of the Steam hardware survey for years. It's taken a back seat to Nvidia's newer RTX 3060 in recent months, but it's still owned by around 4% to 5% of gamers who take part in the Steam hardware survey.

It's starting to age out of relevance, however. The GTX 1650 is four years old, and it's struggling to keep up with modern games like Alan Wake 2 and Avatar: Frontiers of Pandora. Although the GTX 1650 is still a great option for low-lift esports titles like Overwatch 2 and Valorant, you should upgrade if you want to experience AAA games in 2024 and beyond.

Read more