AI chatbot cryptojacking campaign targeting high-performance GPU users
Campaign
Summary
Hide ▲
Show ▼
Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloads on campaign-specific subdomains of gleeze[.]com associated with Dynu. The pages impersonate tools including CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, with operators focusing on systems with high-performance GPUs. Microsoft said it detected and blocked activity tied to the campaign, which had more than 150 malicious domains and, in April 2026, shifted from conventional search results to links surfaced in LLM-based chatbot responses. The infection chain can install ScreenConnect, tamper with Microsoft Defender exclusions, and deploy miners such as gminer, lolMiner, and SRBMiner-MULTI.
Related Happenings
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
How related:
The supported mining programs are gminer, lolMiner, and SRBMiner-MULTI, all of them designed to use graphics processing units (GPUs).
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityHow related: The supported mining programs are gminer, lolMiner, and SRBMiner-MULTI, all of them designed to use graphics processing units (GPUs).
About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
TCLBanker self-spreading banking trojan
Malware Activity
H score31
First: 08.05.2026 01:06
Last: 08.05.2026 01:06
Sources 1
About this happening:
The TCLBanker trojan now combines trojanized installer delivery with self-spreading worm modules, widening access to 59 banking, fintech, and cryptocurrency platform...
TCLBanker self-spreading banking trojan
Malware ActivityAbout this happening: The TCLBanker trojan now combines trojanized installer delivery with self-spreading worm modules, widening access to 59 banking, fintech, and cryptocurrency platform...
Google Ads tax-search ScreenConnect malvertising campaign
Campaign
H score32
First: 24.03.2026 19:05
Last: 24.03.2026 19:05
Sources 1
About this happening:
A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Google Ads tax-search ScreenConnect malvertising campaign
CampaignAbout this happening: A malvertising campaign active since January 2026 is using Google Ads and tax-related search terms to push rogue ConnectWise ScreenConnect installers, creating a p...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor Meta
H score37
First: 20.02.2026 22:00
Last: 20.02.2026 22:00
Sources 1
About this happening:
A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Jinkusu's Starkiller phishing-as-a-service ecosystem commoditizes account takeover
Threat Actor MetaAbout this happening: A new phishing-as-a-service operation tied to Jinkusu is proxying real login pages through attacker infrastructure, making MFA bypass and account takeover easier for low-s...
Timeline
-
27.05.2026 10:45 3 articles · 1mo ago
Microsoft warns of AI chatbot-led cryptojacking campaign
Initial DisclosureMicrosoft warned of an active cryptojacking campaign that uses AI chatbot interactions and SEO-poisoned download sites to steer users toward malicious ZIP archives hosted on campaign-specific subdomains of gleeze[.]com associated with Dynu. The campaign impersonates trusted utilities such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear, with a focus on users who own high-performance GPUs. Microsoft said it detected and blocked activity tied to the campaign, and noted that observed iterations in April 2026 shifted delivery from conventional search results to links surfaced in LLM-based chatbot responses.
Show sources
- AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites — thehackernews.com — 27.05.2026 10:45
- AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites — thehackernews.com — 27.05.2026 10:45
- GPU mining malware spreads via SEO poisoning, AI chatbots — www.bleepingcomputer.com — 28.05.2026 00:31