This malware steals social media credentials under ChatGPT app disguise

The website then directs users to download a purported ChatGPT version for Windows, which is actually an archive containing an executable file

cyber security, malware, cyber crime
IANS New Delhi
2 min read Last Updated : Feb 23 2023 | 7:55 PM IST

A team of researchers have identified a new and ongoing malware campaign that capitalises on the increasing popularity of the ChatGPT AI chatbot, a new report said on Thursday.

According to cybersecurity firm Kaspersky, cybercriminals are distributing the malware via Facebook communities, offering a fake desktop version of ChatGPT.

"This campaign targeting ChatGPT is a prime example of how attackers are leveraging social engineering techniques to exploit the trust that users place on popular brands and services. It is important for users to understand that, just because a service appears to be legitimate, it doesn't mean that it is," said Darya Ivanova, a security expert at Kaspersky.

Other than the bot, users are infected with the Fobo Trojan, which steals sensitive data such as Facebook, TikTok, and Google account credentials, as well as personal and corporate financial information.

When users click on the link in the post, they are directed to a well-designed website that looks almost identical to the official ChatGPT website, said the report.

The website then directs users to download a purported ChatGPT version for Windows, which is actually an archive containing an executable file.

The installation process then begins but abruptly ends with an error message stating that the programme could not be installed.

In fact, the installation of the program proceeds without the users' knowledge and a new stealer Trojan, Trojan-PSW.Win64.Fobo, is installed on the user's computer, according to the report.

This Trojan is intended to steal information about saved accounts from browsers such as Chrome, Edge, Firefox, and Brave.

As part of the attack, the Trojan steals login credentials as well as attempts to obtain additional information, such as the amount of advertising money and the current balance of the business accounts.

The attackers are going after the global market. Users in Africa, Asia, Europe, and America have been targeted by the fraudulent "desktop client" for ChatGPT, the report mentioned.

--IANS

shs/vd

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :ChatbotMalware

First Published: Feb 23 2023 | 7:55 PM IST

Next Story