Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass Disinformation, Malvertising, and Cryptojacking
Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot (TL-2026-2631), also tracked as AI Recommendation Poisoning, is a high-severity tracked intrusion set, first published 2026-09-23. It is attributed to Pravda network operators for the disinformation thread (Russia) with low confidence, affects OpenAI ChatGPT, maps to 16 MITRE ATT&CK / ATLAS techniques (AML.T0051, T1036.005, T1053.005), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-2631
- Threat ID
- TL-2026-2631
- Also known as
- AI Recommendation Poisoning, LLM Grooming, Generative Engine Optimization (GEO) Abuse, AI Chatbot SEO Poisoning, LLMShare
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-23
- Last reviewed
- 2026-09-23
- Attribution
- Pravda network operators for the disinformation thread
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, health, legal, government administration, education, generalpublic
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot
Malware and tooling: GROK, Lumma, Lumma Stealer - S1213, SRBMiner-MULTI, Satacom, Vidar, gminer, lolMiner, ScreenConnect
Multiple independently-operating threat clusters are seeding the web with SEO-optimized malicious pages and prompt-injection payloads so that AI chatbots and AI-generated search summaries (ChatGPT, Google Gemini/AI Overviews, Microsoft Copilot, Claude, Perplexity, Grok) ingest and surface attacker-controlled content as trustworthy. Confirmed technical incidents include a Microsoft-documented cryptojacking campaign where ChatGPT recommended malware-laced software downloads, a 'LLMShare' malvertising scheme abusing ChatGPT/Claude shared-conversation pages, an 'AI Recommendation Poisoning' prompt-injection technique that persists false 'trusted source' instructions in AI assistant memory, and a Kremlin-linked 'Pravda'/Portal Kombat network whose LLM-grooming operation gets false narratives repeated as fact by major chatbots.
How Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot works
This threat tracks the emergent technique class of poisoning AI chatbot and AI-search outputs by manipulating the web content and query parameters those systems ingest, rather than exploiting a software vulnerability. Four distinct, evidence-backed clusters fall under this umbrella:
1. AI-chatbot-driven cryptojacking (Microsoft Defender, disclosed 2026-05-26): threat actors built 150+ malicious subdomains of gleeze[.]com hosted behind Dynu dynamic DNS, impersonating popular system utilities (CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, PDFgear) that target GPU-owning users. Users searching for these tools via search engines AND via AI chatbot software recommendations were directed to the malicious domains. The downloaded ZIP bundles a legitimate executable with a malicious autorun.dll that is sideloaded, which installs a ScreenConnect remote-access client (disguised as vcredist_x64.dll via msiexec.exe) that calls back to 193.42.11.108. SimpleRunPE.exe then establishes six persistence mechanisms, hollows Microsoft-signed binaries, disables Defender exclusions, checks for analysis tools (taskmgr.exe, Process Hacker, Process Explorer, System Informer), and deploys one of three GPU cryptominers (gminer, lolMiner, SRBMiner-MULTI). The established ScreenConnect access could later support data theft, lateral movement, or ransomware.
2. LLMShare malvertising (Push Security, disclosed 2026-05-29): attackers abuse the native 'share' features of ChatGPT and Claude to host convincing fake service-disruption notices or fake installation guides at trusted chatgpt.com/s/ and claude.ai/share/ URLs, then drive traffic to them via malvertising/SEO on searches for 'chatgpt', 'chatgpt free', and common typos. Clicking through redirects to a ChatGPT clone at openew[.]app that delivers a VirusTotal-flagged malicious executable. The infrastructure conditionally renders a benign generic AR/VR page to automated scanners while showing the malicious flow to real victims.
3. AI Recommendation Poisoning / prompt injection (Microsoft, disclosed 2026-02-10): legitimate businesses (and by extension, attackers) embed hidden instructions in 'Summarize with AI' deep-link URLs (e.g. copilot.microsoft.com/?q=..., chat.openai.com/?q=..., claude.ai/new?q=...) that, when clicked, cause the assistant to permanently 'remember' a domain as a trusted citation source or accept injected marketing copy as product fact. Microsoft found over 50 unique prompts from 31 companies across finance, healthcare, legal, SaaS, and security sectors. Enabling tooling includes the npm package CiteMET and the 'AI Share URL Creator' web tool, both marketed openly as 'SEO growth hacks for LLMs.' This is the same mechanism a malicious actor could use to poison AI assistant memory toward phishing or malware-serving domains.
4. LLM grooming for disinformation (NewsGuard investigations, ongoing through 2026): the Pravda network (aka Portal Kombat, identified by France's Viginum in Feb 2024) is a cluster of 370+ pro-Russian websites that published roughly 6 million articles in 2025 across dozens of languages, engineered less for human readers than for AI training-data and retrieval-augmented ingestion. NewsGuard's repeated testing of ChatGPT, Copilot, Mistral's chat, and Google AI Overviews/Lens found major chatbots repeating Pravda-seeded false narratives as verified fact in 33% of cases (March 2025) rising to roughly half of tested cases by January 2026. Storm-1516, an influence operation associated with former Florida deputy sheriff John Mark Dougan (now based in Russia), has been documented theorizing AI-targeted disinformation strategies.
A related, adjacent pattern documented by ZeroFox and Huntress uses .edu/.gov-hosted fake PDFs and forum reposts to seed false brand customer-support phone numbers that AI Overviews, Gemini, and ChatGPT then surface to users as legitimate contact information -- a phishing/vishing precursor technique using the same SEO-poisoning primitive. Zscaler ThreatLabz separately documented black-hat SEO campaigns using AI-tool branding (ChatGPT, Luma AI) on WordPress sites with multi-layer JS redirection to distribute the Vidar and Lumma infostealers and Legion Loader.
Collectively these clusters demonstrate that AI chatbots' real-time web retrieval and citation behavior can be reliably manipulated at scale using nothing more than search-engine-optimized content, malvertising, and crafted URLs -- no exploit or CVE required -- letting attackers bypass traditional security scrutiny (URL reputation, spam filters) because the malicious link or claim arrives wrapped in a trusted AI-synthesized response.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2631
Execution
AML.T0051 LLM Prompt Injection; T1204.001 Malicious Link
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1218.007 Msiexec
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Command and Control
Impact
Discovery
T1518.001 Security Software Discovery
stealth
Resource Development
T1583.001 Domains; T1583.008 Malvertising; T1608.001 Upload Malware; T1608.006 SEO Poisoning
defense-impairment
Affected products and versions in Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot
- OpenAI — ChatGPT
Vulnerable versions: web app, shared-conversation feature, deep-link ?q= prompts
Fixed in: N/A - platform-side prompt-filtering mitigation, not a version - Google — Gemini / AI Overviews / Google Lens
Vulnerable versions: production search-integrated AI summaries
Fixed in: N/A - platform-side mitigation, not a version - Microsoft — Copilot / Microsoft 365 Copilot
Vulnerable versions: production, deep-link ?q= prompts
Fixed in: N/A - Microsoft has deployed prompt-filtering and memory-visibility mitigations - Anthropic — Claude (chat.claude.ai, shared-conversation feature)
Vulnerable versions: production, claude.ai/share/ and claude.ai/new?q= endpoints
Fixed in: N/A - platform-side mitigation, not a version - Perplexity AI — Perplexity
Vulnerable versions: production AI-search summaries
Fixed in: N/A - xAI — Grok
Vulnerable versions: production AI-search summaries
Fixed in: N/A - Mistral AI — Le Chat
Vulnerable versions: production chat responses
Fixed in: N/A
Remediation for Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot
Patches
- No vendor CVE/patch applies -- mitigations are platform-side (OpenAI/Google/Microsoft/Anthropic prompt-filtering and memory-visibility controls) and organizational (SEO/brand monitoring), not a software vulnerability fix
Immediate actions
- Block gleeze.com subdomains and 193.42.11.108 at DNS/web-proxy/firewall layer
- Block openew.app and alert on chatgpt.com/s/ or claude.ai/share/ links that lead to a non-first-party executable download
- Alert on msiexec.exe spawning ScreenConnect (or other RMM) installers, and on Microsoft Defender exclusion-list modifications
- Hunt for SimpleRunPE.exe, RuntimeHost.exe, autorun.dll, and vcredist_x64.dll outside expected installer paths
Workarounds
- Download software only from the vendor's official domain, never a link surfaced inside an AI chatbot answer
- Review and clear AI assistant 'memory'/saved-context entries for unexpected 'trusted source' instructions
- Treat AI-cited customer-support phone numbers and contact details as unverified until confirmed on the official corporate site
Longer-term hardening
- Deploy AI-response / brand monitoring to detect poisoned citations of your organization's name or support contacts in ChatGPT, Gemini, Copilot, and AI Overviews
- Establish continuous SEO/content-poisoning monitoring for corporate support pages and third-party document repositories (.edu/.gov PDF uploads, Pastebin, forums)
- Apply prompt-injection / context-poisoning filtering on 'Summarize with AI' style deep-link query parameters, per Microsoft's published mitigation guidance
- Educate users that AI chatbot software/download recommendations are not vetted the way search-engine results are, and should be verified against the vendor's official domain
Timeline of Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot
- France's Viginum agency identifies the 'Portal Kombat' pro-Russian disinformation network, later dubbed Pravda -- hundreds of websites engineered to seed content for AI chatbot ingestion.
- NewsGuard tests major commercial AI chatbots against five Pravda-linked false narratives and finds them repeated as verified fact in 33% of cases.
- Zscaler ThreatLabz documents a black-hat SEO poisoning campaign using WordPress sites and AI-tool branding (ChatGPT, Luma AI) with multi-layer JavaScript redirection to distribute Vidar, Lumma, and Legion Loader.
- A related SEO poisoning campaign disguising malware as AI tools is reported to have targeted more than 8,500 SMB users.
- Google AI Overviews is found surfacing fraudulent customer-service phone numbers seeded via SEO-poisoned content, routing users to scam call centers.
- NewsGuard's follow-up test finds roughly half of tested chatbot responses still repeat Pravda-linked false narratives as fact.
- A documented experiment shows a single fabricated article gets repeated as fact by Google AI Overviews and ChatGPT within 24 hours of publication.
- Microsoft Security publishes research on 'AI Recommendation Poisoning,' documenting 50+ prompt-injection instructions from 31 companies embedded in 'Summarize with AI' deep links to bias Copilot, ChatGPT, Claude, Perplexity, Gemini, and Grok toward chosen sources.
- Attacker-registered subdomains of gleeze.com begin serving trojanized installers for popular system utilities, eventually growing to more than 150 malicious domains.
- Microsoft Defender telemetry captures users being directed to gleeze.com malware downloads via AI chatbot software-recommendation responses rather than traditional search results.
- Microsoft publishes 'From poisoned search results to GPU mining,' detailing the ScreenConnect-and-cryptominer campaign abusing AI chatbot recommendations.
- The Hacker News and BleepingComputer report on the AI-chatbot-driven cryptojacking campaign, amplifying the Microsoft findings.
- Push Security discloses 'LLMShare,' a malvertising technique abusing ChatGPT and Claude shared-conversation pages plus a chatgpt.com clone (openew.app) to deliver malware via search ads.
- France 24 publishes NewsGuard's findings on continued pro-Russian disinformation pollution of AI chatbot responses, naming Storm-1516 operator John Mark Dougan.
Sources cited for Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot
- Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
- AI-Themed SEO Poisoning Attacks Spread Info, Crypto Stealers
- Black Hat SEO Poisoning Search Engine Results For AI to Distribute Malware
- LLMShare: using shared chatbot pages to distribute malware
- AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
- From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
- GPU mining malware spreads via SEO poisoning, AI chatbots
- SEO Poisoning: How Threat Actors Are Tricking AI Models like ChatGPT, Gemini, and CoPilot
- Manipulating AI memory for profit: The rise of AI Recommendation Poisoning
- AI chatbot responses polluted by pro-Russian disinformation
- What Is AI Poisoning? How Attackers Corrupt AI Responses
- Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency
More in threat intel
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users
- UK establishes National Centre for Information Defence to counter Russian state disinformation operations
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel
- Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation
Detection coverage for TL-2026-2631
As of 2026-09-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2631 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.