logo

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

ID: 7442ba7b-0072-51c2-9663-a4605f32a79b

STIX ID: report--7442ba7b-0072-51c2-9663-a4605f32a79b

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: [email protected] (The Hacker News)

...
...

Microsoft reported an active cryptojacking campaign that leverages AI chatbot recommendations and SEO-poisoned sites to trick users into downloading trojanized installers impersonating utilities. The payload sideloads a malicious DLL which installs ScreenConnect for persistent remote access, uses process hollowing and Defender exclusion tampering to run GPU miners (gminer, lolMiner, SRBMiner-MULTI), and can be used for follow-on activity (data theft, lateral movement, ransomware); over 150 malicious domains and infrastructure details (e.g., 193.42.11.108, gleeze.com subdomains, Dynu hosting) were identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.