Feeds2.Feedburner Cryptojacking Malware Exploits AI Chatbots and SEO Poisoning
Article Content
- •Attackers exploit AI chatbots and SEO poisoning to distribute cryptojacking malware.
- •Malware targets high-performance PCs by impersonating trusted software utilities.
- •Persistent access is established via ScreenConnect, enabling further exploitation.
A new cryptojacking campaign is targeting high-performance PC users through malicious downloads disguised as trusted utilities. Attackers leverage SEO poisoning and AI chatbot manipulation to direct users to fake download sites for software like CrystalDiskInfo and HWMonitor. Once downloaded, the malware establishes persistent access using the legitimate remote management tool ScreenConnect, allowing for potential data theft and further exploitation. Microsoft has confirmed the campaign's existence and noted that it focuses on systems with high GPU capabilities to maximize mining output. The malware employs DLL sideloading and process hollowing techniques to evade detection. This campaign highlights the vulnerabilities in AI chatbot recommendations and the ease with which they can be manipulated. Users are advised to avoid relying on AI for software downloads and to verify sources manually. Microsoft Defender has implemented measures to detect and block associated threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (20)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…