The images in this article were generated with artificial intelligence. How we publish
Microsoft has alerted about an active campaign of cryptojacking that incorporates a worrying news: attackers are taking advantage of interactions with chatbots based on large language models to direct victims to malicious download sites. This technique extends the old practice of SEO poisoning - manipulating results to show infectious links - to a new terrain, where the apparently "conversational" recommendation of an IA serves as a vector of confidence for the user.
The technical scheme is deliberate and selective. Instead of indiscriminately infecting thousands of equipment, operators plant legitimate diagnostic or software utilities used by users with powerful GPUs (e.g. tools to monitor hardware or codecs packages) to maximize mine performance by committed equipment. The downloaded ZIP file usually contains a legitimate executable along with a malicious DLL that is loaded by sideloading; this DLL itself installs a remote access component (ScreenConnect / ConnectWise Control), which allows the attacker to deploy persistent mechanisms, run miners (gminer, lolMiner, SRBMiner-MULTI) and maintain control for later activities such as data theft or ransomware.

The use of legitimate administrative tools and reliable suppliers converted into "channel" - from dynamic DNS services to domain to remote managers included by third parties - is the same recipe that has used the advanced threat: exploit organizational trust to hide malicious activity. Microsoft has also documented in parallel intrusions that start with exposed applications or abuse of third-party suppliers, where unpatched failures, Kerberos relay and account abuse are combined with excessive privileges to move laterally.
This has several operational implications. First, one must assume that the automatic recommendations of an IA are not a security guarantee: a link that appears in a chatbot response may have been manipulated by poisoning techniques. Second, persistence through legitimate tools complicates detection, because visible signals (signed processes, known services) can mask malicious actions. Thirdly, the orientation to GPUs indicates that attackers seek to optimize benefits per incident, so organizations with intensive computing capacity are particularly valuable objectives.
The recommended actions combine technical and behavioural measures. From the user and security team perspective, always check the source of a download: confirm that the domain belongs to the official supplier, compare the installer's digital sums and signatures and avoid downloading software from unverified links. At the organizational level, effectively filtered DNS and blocked suspicious domains, restricts downloads and executions through allowlisting, monitors and limits outgoing connections to unknown remote servers, and reviews the exceptions configured in malware solutions to detect unexpected changes.
In detection and research, pay attention to specific indicators described by analysts: the presence of new keys in Run of registration or programmed tasks that launch binaries with imitative names, creation of ScreenConnect / ConnectWise Control customers to remote servers, use of msiexec to deploy payloads, and process holding techniques that execute signed binary mining code. The use of EDR with memory analysis and process injection detection capabilities facilitates the identification of these techniques. If you identify active mining, preserve logs, capture samples and isolate the machine to avoid lateral movement.
Do not underestimate the risk from third parties: review privileges and access of suppliers, apply principles of less privilege and network segmentation, and audit accounts with sudo or administrative rights. The threat shows that attacks that take advantage of trust relationships can remain long without resorting to noisy vectors; therefore, continuous validation of supplier behaviour and verification of the integrity of remote management communications They're crucial.

It is also necessary to incorporate specific controls against the new IA-based delivery route: educate users to contrast any download recommendation with official sources and not to impulsively click on links originating from automatic responses; consider policies that limit the use of public LLM for queries involving downloading software or accessing sensitive resources, and add human verification steps in processes that depend on automated recommendations.
To deepen the technical risks and the CVE cited in related incidents, see public reference sources such as the Microsoft security blog and NVD NIST database. The first offers general analysis and mitigation ( Microsoft Security Blog) and the second list of known vulnerabilities and their details ( CVE-2025-33073 in NVD). If your environment uses ConnectWise / ScreenConnect, check the supplier's official guides and default settings to avoid abuse ( ConnectWise Control).
In short, the convergence of SEO / AI techniques with the abuse of legitimate tools and the focus on high-value resources requires a response that combines scepticism with automated recommendations, tightening of implementation and access controls, and stricter third-party governance. To assume that trust should not be blind and to continuously validate behaviour within the network is today an essential defense.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...