Hackers are abusing ChatGPT’s Custom GPT feature to impersonate AI products and trick users into installing a sophisticated remote access trojan (RAT), according to Huntress researchers. The campaign turns a trusted ChatGPT-hosted page into the opening stage of a ClickFix attack, combining malvertising, fake verification prompts, obfuscated PowerShell, malicious MSI packages, and DLL sideloading. Huntress investigated at least 40 incidents using the campaign’s Google Sites infrastructure, including two infections traced to malicious Custom GPTs. The attack sometimes begins when users search Google for “chatgpt” and click a sponsored result leading to a chatgpt.com address. Attackers named their Custom GPT “Plus 5.6,”...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!