CVE-2025-33073
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. EPSS 37% (97th percentile).
CISA federal remediation date Nov 10 · date passed
Malware · 110 days ago
The campaign has shifted to a cleaner trust path. Users are no longer being steered only by poisoned search results; AI chatbot answers now hand them attacker-controlled download links directly, which makes the fake utility look like a normal recommendation and helps the lure reach GPU-rich Windows systems.
Microsoft says it has identified more than 150 malicious domains tied to the campaign. The fake downloads impersonate CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, and the operators also use ScreenConnect on compromised hosts for later theft, lateral movement, or ransomware.
That changes the defense problem. Blocking bad search results is not enough when the lure arrives inside generated answers, and the same software-download habit can now feed persistent cryptojacking on the high-GPU machines attackers value most.
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. EPSS 37% (97th percentile).
CISA federal remediation date Nov 10 · date passed
4 sources covering this story
AI chatbot recommendations lure users to cryptojacking malware sites - Help Net Security
Microsoft warned of a cryptojacking campaign using AI chatbot responses and poisoned search results to spread malware targeting GPU systems.
GPU mining malware spreads via SEO poisoning, AI chatbots
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations.
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
Microsoft uncovered 150+ AI-assisted cryptojacking domains using fake software downloads to deploy persistent malware.
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security
Fake AI installers on GitHub and SourceForge drop Deno RAT malware that steals crypto wallets and hijacks Edge for stealth screen streaming.
Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots.
Part of the PlainSec briefing for 2026-05-27