Find notable cyber news and cases, enriched with sources, timelines, and signals.

AI chatbot cryptojacking campaign targeting high-performance GPU users

Campaign
First reported
Last updated
Happening score
H score 51
2 unique sources, 2 articles

Summary

Hide ▲

Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloads on campaign-specific subdomains of gleeze[.]com associated with Dynu. The pages impersonate tools including CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, with operators focusing on systems with high-performance GPUs. Microsoft said it detected and blocked activity tied to the campaign, which had more than 150 malicious domains and, in April 2026, shifted from conventional search results to links surfaced in LLM-based chatbot responses. The infection chain can install ScreenConnect, tamper with Microsoft Defender exclusions, and deploy miners such as gminer, lolMiner, and SRBMiner-MULTI.

Related Happenings

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

How related: The supported mining programs are gminer, lolMiner, and SRBMiner-MULTI, all of them designed to use graphics processing units (GPUs).

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

TCLBanker self-spreading banking trojan

Malware Activity
H score31 First: 08.05.2026 01:06 Last: 08.05.2026 01:06 Sources 1

About this happening: The TCLBanker trojan now combines trojanized installer delivery with self-spreading worm modules, widening access to 59 banking, fintech, and cryptocurrency platform...

Google Ads tax-search ScreenConnect malvertising campaign

Campaign
H score32 First: 24.03.2026 19:05 Last: 24.03.2026 19:05 Sources 1

About this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...

Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover

Threat Actor Meta
H score37 First: 20.02.2026 22:00 Last: 20.02.2026 22:00 Sources 1

About this happening: A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...

Timeline

  1. 27.05.2026 10:45 3 articles · 1mo ago

    Microsoft warns of AI chatbot-led cryptojacking campaign

    Initial Disclosure

    Microsoft warned of an active cryptojacking campaign that uses AI chatbot interactions and SEO-poisoned download sites to steer users toward malicious ZIP archives hosted on campaign-specific subdomains of gleeze[.]com associated with Dynu. The campaign impersonates trusted utilities such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, with a focus on users who own high-performance GPUs. Microsoft said it detected and blocked activity tied to the campaign, and noted that observed iterations in April 2026 shifted delivery from conventional search results to links surfaced in LLM-based chatbot responses.

    Show sources