AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
Microsoft has identified a cryptojacking campaign utilizing AI chatbots to recommend malicious download sites, a novel approach to social engineering. The campaign impersonates legitimate system utilities like CrystalDiskInfo and targets users with high-performance GPUs, aiming to maximize mining yield. Threat actors establish persistent remote access via ScreenConnect, potentially leading to data theft or ransomware deployment, leveraging techniques like AI-assisted search result poisoning.
This campaign begins with users searching for system utilities and hardware monitoring software, which leads them to malicious websites designed to appear legitimate. However, instead of relying on traditional search engine results, the attackers are now leveraging large language models (LLMs) to generate responses that include links to these malicious sites. Users querying AI chatbots for software recommendations are presented with these links within the generated responses. The campaign’s focus on high-performance GPUs suggests a targeted approach to maximize mining profitability, rather than indiscriminately infecting a large number of machines. The threat actors are not simply focused on financial gain; they are establishing persistent remote access to compromised hosts through ScreenConnect, which could then be used for further malicious activities such as data theft or ransomware deployment. The attack chain is deliberately designed to maximize GPU mining yield per compromised device, utilizing techniques like Registry Run keys, scheduled tasks, and Defender exclusion manipulation to maintain persistence.
