Fake ChatGPT Scam Targets Google Users, Installs Remote-Access Trojan
A recent cybersecurity campaign has been uncovered, using a fake ChatGPT to infect computers and gain access to sensitive information. The scam starts by directing victims to a customized GPT hosted on ChatGPT's legitimate domain through sponsored ads on Google.
The link appears harmless at first, but it leads to a custom GPT created by the attackers named 'Plus 5.6' to mimic the real version of the chatbot.
The fake form responds with a message claiming that the main domain is experiencing availability issues and offers an alternative through a supposed 'backup domain,' which actually executes a malicious PowerShell command when followed.
This allows the attackers to install a remote-access Trojan on the system, granting them control over the desktop, access to files and documents, and even activation of the camera and microphone without the user's knowledge or consent.