This new ChatGPT scam tricks you into installing malware
A malicious custom GPT on chatgpt.com is tricking users into installing Remote Access Trojan (RAT) malware via ClickFix attacks.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A new cybersecurity threat has emerged involving a fake version of ChatGPT that is being used to distribute malware. According to reports from Help Net Security and BleepingComputer, a malicious Custom GPT hosted directly on chatgpt.com is luring users into a trap. This specific scam utilizes what is known as ClickFix attacks to deploy a Remote Access Trojan, commonly referred to as a RAT. This type of malware is designed to grant unauthorized actors the ability to take control of a victim's computer remotely, as noted in coverage from Diario AS. Multiple technology and security outlets are tracking the development of this threat.
BleepingComputer explicitly identifies the method of delivery as the deployment of RAT malware through custom ChatGPTs. Help Net Security emphasizes that the malicious GPT is residing on the official chatgpt.com domain, which may increase the likelihood of users trusting the interface. Meanwhile, ZDNET is reporting on the broader nature of the scam and how it tricks unsuspecting users into installing the harmful software on their local machines. This development is significant because it weaponizes the custom GPT feature to bypass traditional user suspicions. Diario AS reports that the fake ChatGPT has managed to sneak into Google, highlighting the reach of the scam's visibility.
The use of ClickFix attacks represents a specific technical strategy to manipulate users into executing the malware. By leveraging a trusted platform like OpenAI's chatgpt.com, the attackers are able to target a wide demographic of users who utilize artificial intelligence for daily tasks. Future monitoring will focus on how the scam continues to operate and whether more custom GPTs are found utilizing these RAT deployment methods. The coverage from ZDNET, BleepingComputer, Help Net Security, and Diario AS suggests that the primary risk remains the installation of the RAT, which allows for the total takeover of a computer. Users are cautioned about the risks associated with third-party custom GPTs that prompt the installation of external software or provide suspicious links intended to fix perceived errors.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 6h ago.
Quick answers
Where is the malicious GPT hosted?
According to Help Net Security, the malicious Custom GPT is hosted on chatgpt.com.
What type of malware is being deployed?
BleepingComputer and Help Net Security report that a Remote Access Trojan (RAT) is being deployed.
What attack method is being used to install the malware?
BleepingComputer states that the custom ChatGPTs are pushing ClickFix attacks to deploy the malware.
Coverage (4)
- A fake ChatGPT sneaks into Google and can take control of your computer: Here’s how the scam works Diario AS · 1d ago
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware BleepingComputer · 1d ago
- Malicious Custom GPT on chatgpt.com lures users into installing a RAT Help Net Security · 1d ago
- This new ChatGPT scam tricks you into installing malware ZDNET · 1d ago
Topics
Related trends
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
1 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
OpenAI Safety Employee Quits, Calls for Nuclear-Level Safeguards
1 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
'We can't trust them completely': AI research fellows warn that labs are running models with the safeguards off behind closed doors
Elite AI research fellows are sounding alarms over the internal removal of safeguards at frontier labs, sparking a grassroots rebellion within the industry.
OpenAI safety leader David Robinson resigns as the team's upheaval mounts
OpenAI safety leader David Robinson resigns amid mounting team upheaval, calling for nuclear-level safeguards.
Apple will limit Mac disk access as AI agents ‘substantially’ increase risk
Apple is changing Mac full-disk access permissions to safeguard user data as AI agents increase security risks.
OpenAI’s Dot agent is enterprise software that can also order your dinner
OpenAI introduces Dot, a dual-purpose agent designed for enterprise workflows alongside consumer tasks like dinner ordering.