Microsoft warns of an active cryptojacking campaign that uses AI chatbot interactions, along with poisoned search results, to steer users to malicious download sites. The technique goes beyond traditional search-based social engineering by embedding harmful prompts and recommendations in the context of AI chat help. Microsoft says attackers deliberately target well-known, legitimate software brands associated with PC and hardware enthusiasts. Reported impersonated tools include CrystalDiskInfo, HWMonitor, Display Driver Uninstaller (DDU), FurMark, K-Lite Codec Pack, and PDFgear. The campaign operates by causing users to land on counterfeit download pages that deliver cryptojacking malware rather than the requested applications. In Microsoft’s description, the method increases the visibility of attacker-controlled recommendations and improves the chances of successful infection compared with conventional search-result poisoning alone. Microsoft attributes the warning to findings from Microsoft Defender experts and frames the activity as an “emerging delivery technique” that extends social engineering into chatbot-driven discovery of software downloads.