Security News > 2023 > February > Hackers use fake ChatGPT apps to push Windows, Android malware
Threat actors are exploiting the popularity of OpenAI's ChatGPT chatbot to distribute malware for Windows and Android, or direct unsuspecting vitims to phishing pages.
Security researcher Dominic Alvieri was among the first to notice one such example using the domain "Chat-gpt-pc.online" to infect visitors with the Redline info-stealing malware under the guise of a download for a ChatGPT Windows desktop client.
Alvieri also spotted fake ChatGPT apps being promoted on Google Play and third-party Android app stores, to push dubious software onto people's devices.
Researchers at Cyble have published a relevant report today where they present additional findings regarding the malware distribution campaign discovered by Alvieri, as well as other malicious operations exploiting ChatGPT's popularity.
ChatGPT is exclusively an online-based tool available only at "Chat.openai.com" and does not offer any mobile or desktop apps for any operating systems at the moment.
Any other apps or sites claiming to be ChatGPT are fakes attempting to scam or infect with malware and should be considered at least suspicious and users should avoid them.
News URL
Related news
- Russia targets Ukrainian conscripts with Windows, Android malware (source)
- FIN7 hackers launch deepfake nude “generator” sites to spread malware (source)
- N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware (source)
- OpenAI confirms threat actors use ChatGPT to write malware (source)
- Iranian hackers now exploit Windows flaw to elevate privileges (source)
- TrickMo malware steals Android PINs using fake lock screen (source)
- North Korean ScarCruft Exploits Windows Zero-Day to Spread RokRAT Malware (source)
- Android malware "FakeCall" now reroutes bank calls to attackers (source)
- New FakeCall Malware Variant Hijacks Android Devices for Fraudulent Banking Calls (source)
- New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers (source)