Microsoft Catches Chatbots Pointing Users at Cryptojacking Sites

A campaign tracked by Microsoft Defender Experts is poisoning AI assistant answers so that download recommendations lead to miner-laden installers.

ThreatVectr Newsdesk· 2 min read
Microsoft Catches Chatbots Pointing Users at Cryptojacking Sites
Share

Microsoft has flagged an ongoing cryptojacking operation in which attackers are seeding malicious download pages into the answers given by AI chatbots, turning conversational assistants into a fresh distribution channel for coin miners.

The alert comes from Microsoft Defender Experts, who describe the technique as a deliberate extension of social engineering past the familiar territory of poisoned search results. Users ask an assistant where to grab a particular utility. The assistant, drawing on indexed content the attackers have salted, suggests a site that looks reputable. The installer arrives with an unwanted XMRig-style passenger.

This is, predictably, the logical next step from SEO poisoning. Attackers have spent years tuning content so that Google ranks their lookalike sites near the top for niche software queries. Large language models trained or grounded on much of the same web inherit much of the same garbage. The assistants strip away the URL cues users sometimes use to spot a dodgy result, and present a single confident recommendation instead.

Microsoft's note (brief, as these things go) frames the shift as a visibility problem. A poisoned chatbot answer carries an implicit endorsement that a tenth-ranked search result does not. Defenders who have been telling staff to "check the URL before downloading" now have to explain why the chatbot's suggestion is the URL to check.

The payload end of the campaign is unglamorous. Cryptojackers want CPU cycles, not headlines, and the operators behind these miners tend to favour persistence and silence over the noisier ransomware playbook. Detection guidance from Redmond points to the usual indicators: unsigned installers from freshly registered domains, sustained high CPU on endpoints that should be idle, outbound connections to known mining pools. None of that is new. The delivery wrapper is.

And that wrapper matters for procurement teams who have spent the past eighteen months bolting AI assistants into helpdesk flows and developer tooling. If an internal copilot is grounded on web search, it inherits whatever the open web is currently being tricked into believing. Output filtering on download URLs is not, at present, a default feature of most enterprise AI deployments.

Microsoft has not attributed the activity to a named group and has not published CVE-class indicators, since there is no vulnerability here in the traditional sense. The bug is in the trust model.

Expect more of this. Search engines spent two decades learning to demote SEO-poisoned pages. Chatbots are starting from roughly where Google was in 2003, and the people gaming them have twenty years of practice.

© 2026 Threat Vectr