Malicious custom ChatGPTs deploy RAT malware via ClickFix attack
Attackers are promoting malicious custom versions of ChatGPT in sponsored Google search results that direct users to fake backup sites, leading to the installation of a remote access trojan (RAT). If users follow the instructions, including running a PowerShell command, their machines are compromised, allowing attackers remote access and surveillance. At least 40 incidents have been traced to the campaign, which uses ChatGPT-hosted instructions to gain victims' trust. OpenAI has since removed at least one malicious GPT.
- Malicious ChatGPTs promoted via Google ads distribute malware
- Victims are tricked into running PowerShell commands
- Malware provides attackers remote access and surveillance
- OpenAI removed known malicious GPTs, but attacks continued
- Attackers built custom encrypted archives to conceal malware
Sources covering this
In this story
More in Cybersecurity
Critical zero-days in Citrix NetScaler exploited, patches released
Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited.
Dutch police arrest former hacker in ShinyHunters probe
Dutch police have arrested Pepijn van der Stap, a previously convicted hacker, in connection with an ongoing investigation into the…
Apple fixes CoreGraphics flaw after targeted attacks
Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly…
New Spectre BTR attack exposes Linux root password hashes
Researchers have unveiled a new Spectre Variant 2 attack, named Branch Target Reuse (BTR), that can extract root password hashes from…