The campaign has shifted to a cleaner trust path. Users are no longer being steered only by poisoned search results; AI chatbot answers now hand them attacker-controlled download links directly, which makes the fake utility look like a normal recommendation and helps the lure reach GPU-rich Windows systems.
Microsoft says it has identified more than 150 malicious domains tied to the campaign. The fake downloads impersonate CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, and the operators also use ScreenConnect on compromised hosts for later theft, lateral movement, or ransomware.
That changes the defense problem. Blocking bad search results is not enough when the lure arrives inside generated answers, and the same software-download habit can now feed persistent cryptojacking on the high-GPU machines attackers value most.