Microsoft: AI Chatbots Now Serving Cryptojacking Links

SkimNews Take
AI chatbots can be exploited as an attack vector for social engineering, as their conversational interface may lend an air of legitimacy to malicious recommendations that users might otherwise question from traditional search results.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft warned that users querying AI chatbots for software downloads were being shown links to attacker-controlled domains inside generated responses, marking a shift from search-engine SEO poisoning to LLM-based delivery observed in April 2026
- The campaign impersonates legitimate GPU-related utilities — CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear — to compromise systems with higher mining yield rather than indiscriminately infecting machines
- Microsoft identified more than 150 malicious domains on gleeze[.]com subdomains hosted via Dynu dynamic DNS, each presenting a download button that retrieves a ZIP archive containing a legitimate executable plus a rogue "autorun.dll" that sideloads a ScreenConnect installer
- Beyond mining, the operators deploy ScreenConnect for persistent remote access that can be leveraged for data theft, lateral movement, or ransomware, with the attack chain also configuring Microsoft Defender exclusions and using process hollowing to run miner code under a Microsoft-signed binary
- The final-stage payload (SimpleRunPE.exe, or "vlc.exe" in a PowerShell variant) supports three miners — gminer, lolMiner, and SRBMiner-MULTI — and terminates itself if taskmgr.exe, Process Hacker, Process Explorer, or System Informer is detected
- Microsoft said it detected and blocked activity associated with the campaign, but the tradecraft demonstrates threat actors adapting social engineering to modern user behavior, treating AI chatbot answers as a new top-of-funnel delivery channel
Why it matters: The campaign extends a proven monetization model — SEO poisoning — into LLM responses, with 150+ domains and a triple-miner toolkit signaling an industrial-scale operation rather than a one-off. For GPU owners and enterprise defenders, the assumption that "AI recommended it" no longer adds safety margin against cryptojacking or downstream ransomware pivots via ScreenConnect.



