{"id":56362,"date":"2026-09-08T12:01:41","date_gmt":"2026-09-08T16:01:41","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=56362"},"modified":"2026-09-08T12:01:41","modified_gmt":"2026-09-08T16:01:41","slug":"gputhor-rowhammer-class-attack","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/gputhor-rowhammer-class-attack\/56362\/","title":{"rendered":"GPUThor: another server attack attempt through the GPU"},"content":{"rendered":"<p>How can an industrial server be compromised through its GPU without leaving a trace? Such a complex, largely theoretical attack would typically leverage hardware vulnerabilities. This isn\u2019t even about design flaws in the hardware itself, but about quirks in how it operates \u2014 sometimes at the physical level. A recent <a href=\"https:\/\/gururaj-s.github.io\/assets\/pdf\/CCS26_GPUThor.pdf\" target=\"_blank\" rel=\"noopener nofollow\">paper<\/a> by Canadian researchers at the University of Toronto describes GPUThor \u2014 a new and more effective Rowhammer attack that exploits precisely this kind of hardware behavior in video memory.<\/p>\n<h2>Rowhammer and graphics cards<\/h2>\n<p>GPUThor builds on the idea behind the original attack on RAM, first proposed in 2014 in the Rowhammer <a href=\"https:\/\/users.ece.cmu.edu\/~yoonguk\/papers\/kim-isca14.pdf\" target=\"_blank\" rel=\"noopener nofollow\">research<\/a>. Rowhammer and every attack in its class rest on a simple fact: memory cells aren\u2019t fully isolated from one another. Repeatedly accessing (hammering) the same row of cells can, under certain conditions, corrupt data (that is, flip bits) in neighboring rows. Once that effect is confirmed as possible, all that\u2019s left is finding a way to weaponize it \u2014 for example, by triggering a denial of service or even executing arbitrary code.<\/p>\n<p>So what do servers and graphics accelerators have to do with any of this? As artificial intelligence technologies have taken off, so has demand for hardware that can run large numbers of parallel, similar computations. And the accelerators built into gaming graphics cards are a natural fit for this kind of workload. This makes cloud providers that rent out graphics accelerators to all comers an attractive target for Rowhammer attacks. The hypothetical scenario runs like this: an attacker buys access to a graphics chip, and uses it to try to compromise the provider\u2019s entire infrastructure. This is exactly why attacks on video memory remain a topic of special interest to researchers.<\/p>\n<h2>How the GPUThor attack works<\/h2>\n<p>In the spring of this year, <a href=\"https:\/\/www.kaspersky.ru\/blog\/gddrhammer-geforge-gpubreach-attacks\/41694\/\" target=\"_blank\" rel=\"noopener\">three new papers<\/a> were published \u2014 each demonstrating a different attack on Nvidia accelerators equipped with GDDR6 memory. All three delivered fairly modest results: the most damage was done when the target was a consumer-grade graphics card, while attacks on an industrial accelerator like the Nvidia A6000 proved to be far less effective. On top of that, none of the attacks worked with ECC (error correction code) memory protection enabled.<\/p>\n<p>GPUThor also looks at the possibility of attacking Nvidia\u2019s older Ampere accelerators with GDDR6 memory: the researchers studied the A4000, A4500, A5000, and A6000 models. But the effectiveness of the new method \u2014 measured by the number of cells whose data was forcibly altered \u2014 is significantly higher. The researchers also argue that, in theory, the technique could be applied to newer accelerators as well.<\/p>\n<p><\/p><div id=\"attachment_56353\" style=\"width: 2026px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/09\/07161247\/gputhor-rawhammer-class-attack-results.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-56353\" title=\"GPUThor attack effectiveness\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/09\/07161247\/gputhor-rawhammer-class-attack-results.png\" width=\"2016\" height=\"590\" alt=\"GPUThor attack effectiveness\" class=\"wp-image-56353 size-full\"><\/a><p id=\"caption-attachment-56353\" class=\"wp-caption-text\">GPUThor\u2019s effectiveness compared to earlier attacks. <a href=\"https:\/\/gputhor.com\/\" target=\"_blank\" rel=\"noopener nofollow\"> Source <\/a><\/p><\/div>;\n<p>How were these results achieved? The standard defense mechanism against Rowhammer attacks is called Target Row Refresh (TRR), which the Canadian researchers took a closer look at. It turns out that if TRR detects repeated access attempts, it forces a refresh of neighboring cells \u2014 making data corruption difficult or impossible. Attackers typically try to defeat TRR by accessing cells at random \u2014 confusing the defense system and reducing its effectiveness. The researchers discovered that on Nvidia Ampere cards, TRR only triggers once every 72 memory-cell refresh cycles. Armed with this finding, they applied an uneven access pattern \u2014 hammering the target cells far more aggressively than before. The result: measured against the original GDDR attack known as GPUHammer as a baseline, GPUThor turns out to be around 7 000 to 23\u00a0000 times more effective.<\/p>\n<h2>Results and outlook<\/h2>\n<p>Combining this more aggressive attack pattern with other refinements produced 72\u00a0000 to 377\u00a0000 bit flips per gigabyte. Earlier Rowhammer variants managed a few hundred at best. This let the researchers achieve double and even triple-bit errors. ECC easily corrects a single-bit error, but not a double-bit one.<\/p>\n<p>The new method also demonstrates the real-world damage a Rowhammer attack could cause: repeated access to video memory using GPUThor triggers a denial of service. The accelerator first reboots, losing data in the process, then flags itself to the administrator as needing replacement.<\/p>\n<p>Despite these impressive research results, GPUThor attacks aren\u2019t successful. For one, the researchers weren\u2019t able to demonstrate arbitrary code execution as a result of the data corruption \u2014 though they claim this is possible even with ECC enabled. For another, an attack thousands of times more effective hints at the theoretical possibility of compromising newer accelerators too, but this also remains unproven for now.<\/p>\n<p>Even so, the Canadian researchers have shown that Rowhammer attacks on graphics accelerators still have untapped potential. It wouldn\u2019t be surprising if future research demonstrated similar attacks against far more advanced devices previously considered highly resistant to them.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"mdr\">\n","protected":false},"excerpt":{"rendered":"<p>Researchers have demonstrated a partially effective Rowhammer attack on graphics accelerators.<\/p>\n","protected":false},"author":665,"featured_media":56363,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,3051],"tags":[4674],"class_list":["post-56362","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","category-enterprise","tag-hardware-vulnerabilities"],"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/gputhor-rowhammer-class-attack\/56362\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/gputhor-rowhammer-class-attack\/42623\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/gputhor-rowhammer-class-attack\/31011\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/hardware-vulnerabilities\/","name":"hardware vulnerabilities"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/665"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=56362"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56362\/revisions"}],"predecessor-version":[{"id":56364,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56362\/revisions\/56364"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/56363"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=56362"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=56362"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=56362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}