ConciseSignal
Following

Malicious custom ChatGPTs deploy RAT malware via ClickFix attack

Attackers are promoting malicious custom versions of ChatGPT in sponsored Google search results that direct users to fake backup sites, leading to the installation of a remote access trojan (RAT). If users follow the instructions, including running a PowerShell command, their machines are compromised, allowing attackers remote access and surveillance. At least 40 incidents have been traced to the campaign, which uses ChatGPT-hosted instructions to gain victims' trust. OpenAI has since removed at least one malicious GPT.

Why it mattersThreat actors are exploiting trust in OpenAI's ChatGPT platform to deliver malware through legitimate domains, increasing the risk of successful attacks. This illustrates new risks associated with custom AI tools and the need for vigilance when interacting with third-party versions of popular platforms.

Sources covering this

SecurityWeekHeadline onlyHackers Use ChatGPT Custom GPTs in ClickFix Attacks1:03 PM →BleepingComputerCustom ChatGPTs push ClickFix attacks to deploy RAT malware8:59 PM →

In this story

Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity