Hackers Abuse AI Chatbot Recommendations to Push Malicious Software Download Links
ID: 15d3285a-2f8e-582e-a2b5-481a7b805fcf
STIX ID: report--15d3285a-2f8e-582e-a2b5-481a7b805fcf
Feed Name: cybersecurityNews.com
Threat Score
This report describes an active AI-assisted cryptojacking campaign in which threat actors poison search results and LLM-based chatbot responses to serve fake installers that sideload malicious DLLs, deploy ScreenConnect for remote access, and run cryptocurrency miners (gminer, lolMiner, SRBMiner-MULTI); Microsoft identified over 150 malicious domains, provided IoCs (domains, IP, SHA256), and recommended EDR/ASR and other mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
