Home · Entertainment · Oct 1 archive

Malware Campaign Uses Real ChatGPT Page to Spread Malware

Confirmed

Entertainment Desk

In Short: Security researchers have uncovered a new malware campaign that uses a real ChatGPT page to trick victims into installing malware.

Chatgpt.com hosted malware attack: ClickFix
YouTube — Travis Briggs

Security researchers have uncovered a new malware campaign that uses a real ChatGPT page to trick victims into installing malware.

Researchers at Huntress discovered that attackers are abusing ChatGPT’s Custom GPT feature to create a bot called “Plus 5.6,” designed to mimic an official OpenAI model.

YouTube — Travis Briggs YouTube

Victims are directed to Plus 5.6 through sponsored Google search results, leading them to a fake GPT page that claims ChatGPT is experiencing availability issues and offers a 'backup domain.

This backup domain opens a Google Sites page that appears to be a Cloudflare security check, instructing users to copy and paste a command into Windows.

The malware campaign, which has been active since September, uses social engineering to trick victims into running attacker-supplied commands on their own machines.

The malware can give attackers extensive control over the infected PC, including the ability to view the screen, search files, use the webcam and microphone, capture system audio, and install more malware.

Researchers have also identified a new CustomGPT linked to the same campaign, and Huntress has warned ChatGPT users to be cautious.

The attackers developed a CustomGPT called Plus 5.6, which is designed to look like the real ChatGPT and impersonate legitimate product offerings.

The malware campaign uses a legitimate function of ChatGPT combined with ClickFix attacks to infect victims with malware.

ClickFix attacks are a popular technique among cybercriminals that use social engineering to trick victims into running attacker-supplied commands on their own machine.

The malware campaign has compromised thousands of legitimate small-business websites to spread this malware trap.

Researchers found that clinics, plumbing companies, online stores, and other businesses were among the victims.

What this adds

This report adds details on how the malware campaign uses social engineering and legitimate-looking websites to trick victims.

Researchers have identified a new CustomGPT linked to the same campaign, indicating ongoing efforts to spread the malware.

The malware campaign has compromised thousands of legitimate small-business websites, expanding the reach of the attack.

The attackers are using a combination of social engineering and legitimate-looking websites to trick victims into installing malware.

Background

Security researchers have uncovered a new malware campaign that uses a real ChatGPT page to trick victims into installing malware.

What's confirmed

What's still developing

Sources