AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html

Publish Date: 2026-05-27 03:45:00

Source Domain: thehackernews.com

  • A cryptojacking campaign by Microsoft involves AI chatbot interactions to recommend malicious download sites, which extends traditional SEO poisoning and social engineering.
  • The campaign targets users with high-performance GPUs by impersonating legitimate system utilities to maximize profitability through cryptocurrency mining.
  • The technique aims to establish persistent remote access to compromised systems using ScreenConnect, enabling additional malicious activities like data theft or ransomware.
  • Attackers use sophisticated methods to ensure persistence, configure Microsoft Defender exclusions, and employ process hollowing to run mining code under trusted binaries.
  • Attack infrastructure uses a subdomain from gleeze[.]com hosted by Dynu, and over 150 malicious domains are identified.
  • The malware deploys three miner programs: gminer, lolMiner, and SRBMiner-MULTI, and takes steps to maintain presence and reconfigure Defender exclusions.
  • Microsoft warns that threat actors continue to exploit over-privileged identities with sudo rights for stealthy persistence and credential theft.
  • Microsoft emphasizes the importance of verifying third-party service providers and management tools to prevent long-term access and credential abuse.