A Real ChatGPT Page Is Being Used to Trick People Into Installing Malware
Huntress said the campaign hit dozens of users and triggered at least 40 incidents as attackers used fake AI prompts to install a remote access trojan.
10 Articles
10 Articles
Infection of the device with malware begins after executing the PowerShell command.
A real ChatGPT page is being used to trick people into installing malware
TL;DR Attackers created a fake ChatGPT model called “Plus 5.6” on the real ChatGPT website. It sent users to a fake security check that tricked them into running a malicious Windows command. That command could install malware that could access files, the screen, the webcam, the microphone, and more. There was a time when spotting a sketchy download meant looking for misspelled websites, strange pop-ups, and other obvious red flags. But that get…
A fake custom GPT redirects users to a page that mimics Cloudflare and asks them to execute commands in Windows, installing Trojans by ClickFix method.
A Custom GPT hosted on ChatGPT convinces victims to reach a false security check that starts a ClickFix chain until the installation of a remote access trojan (RAT).The campaign shows how attackers are transforming trust in AI platforms and legitimate services into a new attack surface The malevolent Custom GPT article: so ChatGPT becomes the first ring of a ClickFix attack comes from Cyber Security 360.
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











