CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

AI-chatbot search-poisoning cryptojacking

campaign · campaign:microsoft-ai-chatbot-search-poisoning-cryptojacking-screenconnect-process-hollow

Microsoft Defender Experts: AI-chatbot search-poisoning extends the SEO-lure pattern; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners (gminer / lolMiner / SRBMiner-MULTI) under a signed Microsoft binary.

Coverage
1
first 2026-05-28 → last 2026-05-28
Latest activity
2026-05-28
Microsoft Defender Experts, AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, finance
Sources cited
2
2 hosts

Defender insights

What each entry about AI-chatbot search-poisoning cryptojacking tells a defender to do, newest first.

2026-05-28NOTABLEMicrosoft Defender Experts, AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners

Story timeline

  1. 2026-05-28Microsoft Defender Experts, AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners under signed Microsoft binary
    researchMicrosoft Defender Experts, AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners

Entries about AI-chatbot search-poisoning cryptojacking (1)

2026-05-28 · view entry permalink →

NOTABLE

Microsoft Defender Experts, AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners under signed Microsoft binary

Microsoft Defender Experts documented an active cryptojacking campaign dating from March 2026 that uses GPU-utility brand impersonation (CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, PDFgear) as initial delivery via SEO poisoning (Microsoft Security Blog, 2026-05-26; The Hacker News, 2026-05-27). The operationally novel evolution is from April 2026: users querying AI chatbots for software-download recommendations were directed to attacker-controlled domains in generated responses, search-poisoning extended into the LLM-generation layer. Delivery chain: (1) fake utility site hosts a ZIP on a gleeze.com subdomain (DDNS via Dynu); (2) ZIP contains the legitimate executable alongside an autorun.dll; (3) DLL side-loading installs vcredist_x64.dll via msiexec.exe, a ScreenConnect packaged installer named to mimic Visual C++ Redistributable; (4) ScreenConnect establishes persistent remote access; (5) the session delivers SimpleRunPE.exe; (6) SimpleRunPE persists via Registry Run keys and scheduled tasks, configures Microsoft Defender exclusions, and uses process hollowing to inject miner code (gminer, lolMiner, SRBMiner-MULTI) into a Microsoft-signed binary. 150+ malicious domains identified since March 2026.

research28 May 05:00Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • microsoft.com1 (50%)
  • thehackernews.com1 (50%)