CVE-2025-33073
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. EPSS 37% (97th percentile).
CISA federal remediation date Nov 10 · date passed
Malware & Tooling · Cryptojacking
The campaign has shifted to a cleaner trust path. Users are no longer being steered only by poisoned search results; AI chatbot answers now hand them attacker-controlled download links directly, which makes the fake utility look like a normal recommendation and helps the lure reach GPU-rich Windows systems.
Microsoft says it has identified more than 150 malicious domains tied to the campaign. The fake downloads impersonate CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, and the operators also use ScreenConnect on compromised hosts for later theft, lateral movement, or ransomware.
That changes the defense problem. Blocking bad search results is not enough when the lure arrives inside generated answers, and the same software-download habit can now feed persistent cryptojacking on the high-GPU machines attackers value most.
4 sources · May 27
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. EPSS 37% (97th percentile).
CISA federal remediation date Nov 10 · date passed
Help Net Security
AI chatbot recommendations lure users to cryptojacking malware sites - Help Net Security
Microsoft warned of a cryptojacking campaign using AI chatbot responses and poisoned search results to spread malware targeting GPU systems.
originalBleepingComputer
GPU mining malware spreads via SEO poisoning, AI chatbots
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations.
originalThe Hacker News
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
Microsoft uncovered 150+ AI-assisted cryptojacking domains using fake software downloads to deploy persistent malware.
originalPart of the PlainSec briefing for 2026-05-27
Every edition of this story: Chatbot Answers Now Deliver Cryptojacking Lures