[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQgOLaRNZ6Hp0GQ5EFPBp3KYupqSKRYJX3SMu_4q2yXM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"023a25a4-31ee-4887-8d3d-4ce67a009b8c","ai-chatbots-exploited-to-distribute-cryptojacking-malware","2f467713-16a2-4e4b-b28f-7f014494a34f","AI Chatbots Exploited to Distribute Cryptojacking Malware","Cybercriminals are now exploiting AI chatbots and LLM-based tools to redirect users to malicious websites hosting cryptojacking malware disguised as legitimate system utilities. This represents a dangerous evolution of social engineering attacks beyond traditional search engine poisoning, targeting users who trust AI recommendations. The campaign specifically targets high-performance GPU systems and establishes persistent access through legitimate remote access tools like ScreenConnect, making detection more challenging. Organizations must recognize that AI chatbots can be manipulated just like any other information source and should not be inherently trusted for software recommendations.","**Immediate actions:**\n- Block or restrict access to untrusted remote access tools like ScreenConnect on corporate networks\n- Implement application allowlisting to prevent unauthorized software installation\n- Deploy endpoint detection and response (EDR) solutions to monitor for process hollowing and DLL sideloading\n\n**Security awareness measures:**\n- Train users to verify software downloads through official vendor websites rather than chatbot recommendations\n- Educate staff about the risks of trusting AI-generated recommendations for software installations\n- Establish clear policies prohibiting the use of AI chatbots for IT-related recommendations\n\n**Supply chain controls:**\n- Maintain an approved software repository with verified legitimate utilities\n- Implement code signing verification for all downloaded executables\n- Monitor network traffic for connections to known cryptomining pools",[12,13,14,15,16,17,18],"CIS Control 2","CIS Control 7","CIS Control 8","CIS Control 13","NIST AC-3","NIST SI-3","NIST AT-2","published","2026-05-27T10:20:34.14975+00:00","2026-05-27T10:20:34.052+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fai-chatbot-recommendations-redirect.html","ai-chatbot-recommendations-redirect-users-to-cryptojacking-malware-sites-7f2826","AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":34,"name":35,"slug":36,"description":37,"color":38},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[40],{"id":41,"date":42,"edition":43,"title":44,"audio_url":45},"0bf775ef-3a7d-492d-8c15-3d6c80cc4010","2026-05-27","afternoon","ThreatNoir Afternoon Brief — May 27","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-05-27\u002Fthreatnoir-afternoon-brief-2026-05-27.mp3"]