A cybersecurity campaign involving malicious software disguised as ChatGPT has been identified by the firm Huntress. The attack leverages sponsored Google search advertisements to direct users toward a custom GPT hosted on the official ChatGPT domain, where they are prompted to download a file that installs a trojan on their computer. Once installed, the malware grants unauthorized actors the ability to control the victim's PC. This discovery highlights a sophisticated method of exploiting legitimate platforms to distribute malicious software to unsuspecting users.
In-depth summary · AI, neutral