Microsoft has identified an active cryptojacking campaign where threat actors use AI chatbots to recommend malicious software download sites, specifically targeting high-performance GPU systems for unauthorized mining.
Key Points
- Attackers use AI-generated responses to direct users toward over 150 malicious domains masquerading as legitimate utilities like FurMark and PDFgear.
- The malware utilizes ScreenConnect for persistent remote access, enabling data theft, lateral movement, and ransomware deployment beyond simple cryptocurrency mining.
- Malicious payloads are delivered via ZIP archives containing legitimate executables paired with rogue DLLs that sideload mining software.
- The campaign specifically targets high-performance hardware to maximize mining yield while actively terminating security tools like Task Manager to avoid detection.
- Microsoft has blocked the associated activity and warns that this "AI search poisoning" represents a significant evolution in traditional social engineering tactics.