Microsoft warns of an active cryptojacking campaign that uses AI chatbot interactions, along with poisoned search results, to steer users to malicious download sites. The technique goes beyond traditional search-based social engineering by embedding harmful prompts and recommendations in the context of AI chat help. Microsoft says attackers deliberately target well-known, legitimate software brands associated with PC and hardware enthusiasts. Reported impersonated tools include CrystalDiskInfo, HWMonitor, Display Driver Uninstaller (DDU), FurMark, K-Lite Codec Pack, and PDFgear. The campaign operates by causing users to land on counterfeit download pages that deliver cryptojacking malware rather than the requested applications. In Microsoft’s description, the method increases the visibility of attacker-controlled recommendations and improves the chances of successful infection compared with conventional search-result poisoning alone. Microsoft attributes the warning to findings from Microsoft Defender experts and frames the activity as an “emerging delivery technique” that extends social engineering into chatbot-driven discovery of software downloads.
Microsoft warns AI chatbot recommendations are used to redirect users to cryptojacking malware
Microsoft warns of an active cryptojacking campaign that uses AI chatbot interactions, along with poisoned search results, to steer users to malicious download sites. The technique goes beyond traditi...
- Microsoft reports an active cryptojacking campaign that uses AI chatbot interactions to redirect users to malicious download sites.
- The technique combines chatbot-based social engineering with poisoned or manipulated search results.
- Attackers impersonate legitimate software brands popular with PC and hardware-focused users.
- Impersonated or targeted applications include CrystalDiskInfo, HWMonitor, Display Driver Uninstaller (DDU), FurMark, K-Lite Codec Pack, and PDFgear.
- The goal of the malicious sites is to deliver cryptojacking malware instead of the requested software.
Cybercriminals are using AI chatbot interactions alongside poisoned search results to direct users to malicious download sites in an active cryptojacking campaign, Microsoft has warned. The campaign impersonates legitimate software tools such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller (DDU), FurMark, K-Lite Codec Pack, and PDFgear. Screenshot of search engine results showing a malicious source of hwmonitor (Source: Microsoft) “The selection of these brands is deliberate. Each application is favored by PC enthusiasts and hardware-focused users, … More → The post AI chatbot recommendations lure users to cryptojacking malware sites appeared first on Help Net Security.
3 months agoMicrosoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites. "This emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations," Microsoft Defender Experts and the Microsoft
3 months ago
Visa expands cybersecurity support for clients amid the rise of AI threats
Visa is expanding support for its clients and for the payments industry as organizations navigate what it describes as a...
Z.ai confirms it created Ox Alpha after anonymous release on OpenRouter
A powerful AI model known as “Ox Alpha” appears online for free and quickly draws attention from developers. It is hoste...
Google offers college students a free year of Gemini AI plans and new study tools
Google is rolling out a back-to-school offer giving eligible college students access to a premium Google AI subscription...