AI Chatbot Recommendations Expose Users to Active Cryptojacking Malware Campaign

Published:

spot_img

AI Chatbot Recommendations Expose Users to Active Cryptojacking Malware Campaign

Microsoft has issued a warning regarding a sophisticated cryptojacking campaign that exploits artificial intelligence (AI) chatbot interactions to direct users to malicious download sites. This emerging tactic represents a significant evolution in social engineering, extending beyond traditional search engine results to increase the visibility of harmful software recommendations.

Evolving Threat Landscape

According to the Microsoft Defender Security Research Team, the campaign impersonates legitimate system utilities such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear. This strategy appears aimed at users with high-performance GPUs, suggesting that attackers are focusing on systems that offer greater mining potential rather than indiscriminately infecting a broad range of devices.

The motivations behind this campaign extend beyond mere financial gain. Threat actors have been observed establishing persistent remote access to compromised systems through ScreenConnect deployments, which could facilitate further malicious activities, including data theft and ransomware attacks. This deliberate approach is designed to maximize GPU mining yield from each compromised device, as opposed to traditional cryptocurrency mining methods that often rely on a larger number of infected machines.

Mechanism of Attack

The attack begins when users search for trusted system utilities and hardware-monitoring software. Malicious sites, manipulated through search engine optimization (SEO) poisoning techniques, appear in the search results. Recent observations indicate that users are increasingly being directed to these harmful sites not just through search engines, but also via interactions with large language model (LLM)-based tools.

In these instances, users querying AI chatbots for software recommendations receive links to domains controlled by attackers. Microsoft noted that this behavior aligns with emerging techniques in AI search result poisoning, extending traditional SEO poisoning methods beyond conventional search engines.

Each malicious site prominently features a download button that retrieves a ZIP archive from a campaign-specific subdomain of gleeze[.]com, a domain hosted by Dynu, a dynamic DNS provider frequently utilized by cybercriminals. Over 150 malicious domains have been identified as part of this campaign.

Technical Details of the Malware

The downloaded ZIP file typically contains a legitimate executable alongside a rogue DLL named “autorun.dll.” This DLL is sideloaded when the user launches the binary, and it is designed to install a second malicious DLL called “vcredist_x64.dll” using “msiexec.exe.” This file serves as a packaged installer for ScreenConnect software.

Once ScreenConnect is installed, it attempts to establish a connection with an attacker-controlled server located at “193.42.11[.]108.” The ScreenConnect session then facilitates the execution of an additional binary known as “SimpleRunPE.exe.” This binary is responsible for establishing persistence on the host through Registry Run keys and scheduled tasks, configuring Microsoft Defender exclusions, and employing process hollowing techniques to execute mining code under a trusted Microsoft-signed binary.

In some cases, instead of using ScreenConnect’s file transfer capabilities to drop the binary, a PowerShell script is employed to fetch the binary from a remote drive, disguise it as “vlc.exe,” create a scheduled task to launch it, and subsequently delete itself.

The hollowed binary communicates with the attacker’s server, transmits extensive host information, downloads the appropriate miner archive at runtime, and executes it. The malware supports three miner programs: gminer, lolMiner, and SRBMiner-MULTI. Additionally, it recreates persistence artifacts to ensure continued presence and reconfigures Defender exclusions if they are removed. The malware actively monitors running processes and terminates the miner if it detects any of the following:

  • taskmgr.exe (Windows Task Manager)
  • processhacker.exe, processhacker2.exe (Process Hacker)
  • procexp.exe, procexp64.exe (Process Explorer)
  • systeminformer.exe (System Informer)

Implications for Cybersecurity

This combination of AI-assisted delivery, software impersonation, and persistent access underscores how threat actors are adapting their strategies to modern user behavior. The disclosure of this campaign comes shortly after Microsoft reported on another incident involving an unknown threat actor who compromised an internet-facing F5 BIG-IP firewall appliance. This breach allowed the attacker to pivot to an internal Linux host, highlighting the ongoing exploitation of internet-facing edge appliances as initial access points.

The compromised Linux host enabled the attacker to conduct extensive reconnaissance and laterally move to a vulnerable Atlassian Confluence server, although attempts to execute remote code through unpatched security flaws were unsuccessful. To circumvent these restrictions, the threat actor established an FTP server on the initial Linux host using Python’s ftplib module to transfer a custom scanning tool to the Confluence server. This was followed by credential theft and subsequent attacks against Windows infrastructure.

In this incident, the threat actor authenticated to a Linux server over SSH using a privileged account, maintaining this level of access throughout the observed activity without establishing explicit persistence mechanisms. This situation highlights the risks associated with over-privileged identities that possess sudo rights.

Conclusion

As cyber threats continue to evolve, organizations must remain vigilant in their cybersecurity practices. The use of AI in facilitating these attacks marks a new frontier in cybercrime, necessitating a proactive approach to threat detection and response. Microsoft emphasizes the importance of deliberate verification, urging organizations to trust their vendors and tools while validating their behavior within their environments.

For further insights into the evolving landscape of cybersecurity threats, including credential interception and third-party abuse, organizations should adopt a comprehensive security posture that anticipates the tactics employed by sophisticated threat actors.

Source: thehackernews.com

Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.

spot_img

Related articles

Recent articles

Krybit Ransomware Emerges as a Contender in 2026’s Competitive RaaS Landscape Amid Rivalry and Operational Challenges

Krybit Ransomware Emerges as a Contender in 2026's Competitive RaaS Landscape Amid Rivalry and Operational Challenges Krybit Ransomware has quickly positioned itself within the increasingly...

European Parliament Revives Chat Control 1.0, Igniting Privacy Debate Over CSAM Scanning

European Parliament Revives Chat Control 1.0, Igniting Privacy Debate Over CSAM Scanning The recent revival of the Chat Control 1.0 framework by the European Parliament...

Inside Declassified: Strengthening Cybersecurity Through Untold Stories from Industry Leaders

Inside Declassified: Strengthening Cybersecurity Through Untold Stories from Industry Leaders In the realm of cybersecurity, behind every significant incident lies a narrative often overlooked in...

Meta Files Patent for AI That Listens All Day and Analyzes Your Emotional State

Meta Files Patent for AI That Listens All Day and Analyzes Your Emotional State Meta Platforms has recently filed a patent application for an artificial...