AI Chatbots Recommend Malicious Sites in New Cryptojacking Campaign Targeting High-End GPUs

3 Sources

Share

Microsoft has uncovered a cryptojacking campaign where AI chatbots unknowingly direct users to malicious download sites. Threat actors manipulate AI recommendations to deliver GPU mining malware disguised as legitimate utilities like CrystalDiskInfo and HWMonitor. The attack establishes persistent remote access via ScreenConnect, enabling data theft and potential ransomware deployment.

AI Chatbots Become New Vector for Malware Distribution

Microsoft has identified an active cryptojacking malware campaign that exploits AI chatbots to redirect users toward malicious download sites

1

. This emerging delivery technique marks a significant shift in how threat actors adapting social engineering strategies to modern user behavior. Instead of relying solely on traditional SEO poisoning methods, attackers now manipulate AI chatbot recommendations to surface links to attacker-controlled domains within generated responses

2

. When users query AI chatbots for software download recommendations, they receive what appears to be legitimate guidance but are actually being directed to malicious websites hosting cryptocurrency mining malware.

Source: Hacker News

Source: Hacker News

Targeting High-Performance Systems with GPU Mining Malware

The campaign specifically impersonates trusted system utilities including CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear—software typically installed by owners of high-performance GPUs

1

. Microsoft researchers determined this represents a deliberate targeting and monetization strategy engineered to maximize GPU mining yield per compromised device rather than indiscriminately infecting large numbers of machines

2

. More than 150 malicious domains have been identified serving these fake utilities, all hosted on campaign-specific subdomains of gleeze[.]com through infrastructure associated with Dynu, a dynamic DNS provider frequently used by cybercriminals

1

.

Multi-Stage Attack Delivers Persistent Remote Access

The malicious download sites contain prominent download buttons that retrieve ZIP archives containing both legitimate executables and rogue DLLs that execute through sideloading techniques

2

. When users launch what appears to be legitimate software, the malicious DLL installs ScreenConnect remote access software, establishing persistent remote access to compromised hosts

1

. This backdoor capability extends the threat beyond financial motivation, enabling follow-on activities such as data theft, lateral movement, or ransomware deployment. The malware employs sophisticated evasion techniques including process hollowing into Microsoft-signed binaries, configuring Microsoft Defender exclusions, and running anti-analysis checks to detect virtual machines and analysis tools

2

.

Evolution from Traditional SEO Poisoning to AI Manipulation

While the campaign initially relied on SEO poisoning to boost malicious sites in search engine rankings, observations from April 2026 indicate a shift toward manipulating AI-based assistants

1

. This represents what Microsoft calls "AI search result poisoning," an extension of traditional SEO poisoning beyond conventional search engines

1

. The technique proves particularly effective because users often trust AI chatbot recommendations without the same level of scrutiny they might apply to search results

3

. Most SEO experts still haven't cracked the code on getting mentioned by AI platforms, yet threat actors have apparently found methods to game these systems

3

.

Source: TechRadar

Source: TechRadar

Understanding the Cryptojacking Operation

Once the malware establishes itself through software impersonation and gains control via ScreenConnect, it profiles the compromised device and downloads one of three supported mining programs: gminer, lolMiner, or SRBMiner-MULTI

2

. The binary recreates persistence artifacts across six mechanisms using Registry Run keys and scheduled tasks to ensure continued presence even if defenders attempt remediation

2

. The malware also monitors running processes and immediately terminates mining operations if it detects analysis tools, demonstrating sophisticated anti-detection capabilities

1

. Victims are left with unusable computers and enormous electricity bills as the cryptojacking operation mines cryptocurrency for attackers

3

.

Source: BleepingComputer

Source: BleepingComputer

Implications for AI-Driven Search and Security

This cybersecurity threat highlights fundamental vulnerabilities as user behavior shifts from traditional search engines toward AI-powered assistants. Microsoft emphasized that this combination of AI-assisted delivery, software impersonation, and persistent access demonstrates how social engineering tactics are evolving

1

. Defenders must now treat AI recommendations with the same caution as search results, verifying links before downloading to avoid compromise

3

. Organizations should monitor for the indicators of compromise included in Microsoft's report and implement defenses that account for this emerging attack vector. The campaign signals that as AI chatbots gain market share from traditional search engines, attackers will continue adapting their malicious download sites and poisoning techniques to exploit user trust in these new platforms.

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved