Malware & Tooling · Cryptojacking

Chatbot Answers Now Deliver Cryptojacking Lures

The campaign has shifted to a cleaner trust path. Users are no longer being steered only by poisoned search results; AI chatbot answers now hand them attacker-controlled download links directly, which makes the fake utility look like a normal recommendation and helps the lure reach GPU-rich Windows systems.

Microsoft says it has identified more than 150 malicious domains tied to the campaign. The fake downloads impersonate CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, and the operators also use ScreenConnect on compromised hosts for later theft, lateral movement, or ransomware.

That changes the defense problem. Blocking bad search results is not enough when the lure arrives inside generated answers, and the same software-download habit can now feed persistent cryptojacking on the high-GPU machines attackers value most.

4 sources · May 27

CVE-2025-33073

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. EPSS 37% (97th percentile).

CISA federal remediation date Nov 10 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-05-27

Every edition of this story: Chatbot Answers Now Deliver Cryptojacking Lures

More from today