Interestana
Home/News/Custom ChatGPTs Used in ClickFix RAT Malware Attacks
BleepingComputer••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Custom ChatGPTs Used in ClickFix RAT Malware Attacks

Malicious actors are exploiting custom variants of OpenAI's ChatGPT, advertised through sponsored Google search results, to direct unsuspecting users to compromised websites. These sites employ ClickFix attacks, a technique that leverages user interaction with seemingly legitimate content to trigger the download and execution of malware. The primary payload identified in these attacks is Remote Access Trojan (RAT) malware, which grants attackers extensive control over the victim's computer. This sophisticated phishing and malware distribution scheme highlights a new frontier in cyber threats, where popular AI tools are being weaponized to bypass traditional security measures and exploit user trust.

The ClickFix attack mechanism involves embedding malicious code within seemingly innocuous elements on a webpage. When a user interacts with these elements, such as clicking on a link, an image, or even hovering over certain content, the attack is initiated without explicit user consent for the malicious action. This method is particularly effective because it can be disguised within the user's natural browsing behavior, making it harder to detect than more overt phishing attempts. The RAT malware, once installed, can perform a wide range of malicious activities, including stealing sensitive data, monitoring user activity, deploying further malware, and providing a backdoor for persistent access to the compromised system.

Researchers at Sucuri, a cybersecurity firm, identified this emerging threat. Their analysis revealed that attackers are creating custom ChatGPT interfaces, likely designed to mimic the official OpenAI product, and then promoting these through paid advertisements on Google. When users click on these ads, they are led to websites that host the ClickFix exploit. The attackers are specifically targeting users who are actively searching for AI tools like ChatGPT, preying on their interest and potential lack of deep technical knowledge regarding online security. The use of sponsored search results suggests a significant investment by the attackers in reaching a broad audience and maximizing the potential number of victims.

This trend underscores a growing concern within the cybersecurity community: the weaponization of AI technologies for malicious purposes. As AI tools become more accessible and integrated into daily online activities, they present new vectors for cyberattacks. The ability to create convincing fake interfaces and leverage sophisticated attack techniques like ClickFix, combined with the broad reach of search engine advertising, makes this particular threat highly concerning. Organizations and individuals are urged to exercise extreme caution when encountering AI tools advertised through search engines, to verify the legitimacy of the source, and to ensure robust cybersecurity measures are in place to detect and prevent malware infections.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next