Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Fake ChatGPT apps are being to distribute malware and steal credit card information
#1
Information 
Quote:Last week, I wrote about why you should avoid downloading ChatGPT apps for Android and iOS. Now, you can add more to the list, malware.

[Image: Fake-ChatGPT-apps-are-distributing-malwa...indows.jpg]

Over the past few months, ChatGPT has steadily been growing in popularity. People are using it for fun, to learn stuff, for research, to write programs, students were even caught for using the chatbot to write their homework.

There's no denying the fact that OpenAI's tool has become an internet sensation. Unsurprisingly, the company introduced a premium tier, called ChatGPT Plus.

The subscription, which costs $20/month is available for users in the U.S., and grants unrestricted access to the chatbot. Unfortunately, ChatGPT's rising popularity has also drawn the attention of hackers. Martin wrote an article about an info-stealing malware called Stealc, where he mentioned another one named Redline.

Fake ChatGPT apps being used to spread malware and steal user data

Attackers have packaged the Redline malware in a ChatGPT app for Windows. The tool was analyzed by a security researcher, Dominic Alvieri, who discovered that it redirects users to a domain that infected visitors with the Redline malware.

[Image: Fake-ChatGPT-social-media-pages-used-for...paigns.jpg]

A report published by Cyble Research and Intelligence Labs (CRIL) goes into more details about how the malware were being distributed. The findings reveal that threat actors were using a Facebook page to promote the malicious app, the page even had ChatGPT logos on it to make it look like it was the real deal, aka malvertising.

BleepingComputer reports that these fake ChatGPT apps were also pushing malware on the Google Play Store. The security firm identified over 50 fake ChatGPT Android apps that were used for nefarious purposes such as billing fraud via SMS to activate subscriptions, and contained different types of malware (adware, spyware) to steak call logs, contacts, messages, media files, etc. These fake apps were using the name and icon (logo) of ChatGPT to trick users.

ChatGPT phishing campaigns

CRIL also discovered that hackers were running some phishing campaigns by cloning ChatGPT's website. The attackers replaced the Try ChatGPT button, which then initiated a download for a malicious file (Lumma Stealer, Aurora Stealer, clipper malware, etc.). The threat actors were also using cloned websites of ChatGPT to lead users to fake a ChatGPT payment page, to steal credit card information from users.

Recently, a number of fake authenticator apps have made their way on to the iOS App Store, after Twitter announced it would be ending support for SMS 2FA for free accounts. Hackers wasted no time to exploit the situation to try and scam users with expensive subscriptions in the fake 2FA apps, and even used them to steal the QR code from users. Apple has taken action on some apps by delisting from its storefront, but many of them still exist.

Google and Apple need to improve their review checks before allowing apps on their stores. There is no official ChatGPT app for Windows, Android, iOS, etc. If you want to use ChatGPT on your phone, just use the official website at chat.openai.com. Bookmark the page, or add a shortcut for it on your mobile's home screen. You may also be interested in Bing Chat, which is now available in 3 of Microsoft's apps for Android and iOS. Access to the AI-powered tool is currently only available via a waitlist.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Thunderbird Supernova 115.10.2
Thunderbird Supern...harlan4096 — 15:31
VirtualBox 7.0.18 Build 162988
Changes in 7.0.168...harlan4096 — 15:25
Emsisoft Anti-Malware 2024.5.0.12426
Changes in 2024.5....harlan4096 — 15:25
Microsoft introduces Passkeys support fo...
Microsoft is celeb...harlan4096 — 15:08
Mozilla blames recaptcha issue in Firefo...
Mozilla confirmed ...harlan4096 — 15:04

[-]
Birthdays
Today's Birthdays
avatar (42)nikitaxople
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (36)owysykan
avatar (47)beautgok
avatar (37)axuben
avatar (43)talsmanthago
avatar (29)mocetor
avatar (44)piomaibhaict
avatar (49)kingbfef
avatar (36)izenesiq
avatar (38)ihijudu
avatar (43)tiojusop
avatar (40)Damiennug
avatar (38)acoraxe
avatar (47)contjrat
avatar (39)axylisyb
avatar (42)tukrublape
avatar (39)iruqi
avatar (40)saitetib
avatar (34)ypasodiny
avatar (37)omapek
avatar (46)Geraldtuh
avatar (42)knigiJow
avatar (44)1stOnecal
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (43)xclubDum
avatar (39)Stewartanilm
avatar (38)GregoryRog
avatar (43)mediumog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>