AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html
Publish Date: 2026-05-27 03:45:00
Source Domain: thehackernews.com
- A cryptojacking campaign by Microsoft involves AI chatbot interactions to recommend malicious download sites, which extends traditional SEO poisoning and social engineering.
- The campaign targets users with high-performance GPUs by impersonating legitimate system utilities to maximize profitability through cryptocurrency mining.
- The technique aims to establish persistent remote access to compromised systems using ScreenConnect, enabling additional malicious activities like data theft or ransomware.
- Attackers use sophisticated methods to ensure persistence, configure Microsoft Defender exclusions, and employ process hollowing to run mining code under trusted binaries.
- Attack infrastructure uses a subdomain from gleeze[.]com hosted by Dynu, and over 150 malicious domains are identified.
- The malware deploys three miner programs: gminer, lolMiner, and SRBMiner-MULTI, and takes steps to maintain presence and reconfigure Defender exclusions.
- Microsoft warns that threat actors continue to exploit over-privileged identities with sudo rights for stealthy persistence and credential theft.
- Microsoft emphasizes the importance of verifying third-party service providers and management tools to prevent long-term access and credential abuse.