Malware Traps Lurk Behind Fake ChatGPT Ads on Google
Researchers at Island have discovered a massive malvertising campaign targeting Windows users. Cybercriminals are abusing the ChatGPT feature to create fake content and trick users into installing malware. The scam uses fake verification pages that ask users to press Win+R and paste commands, which downloads disguised malware onto the computer.
The campaign involved around 850 paid-ad landings, 26 lookalike ChatGPT destinations, and 71 Google Ads campaign IDs over a 3-month period ending in August. The attackers used a 'ClickFix' trap to trick users into executing malicious commands on their own devices.
Once infected, the malware can survive restarts and secretly communicate with attackers through a Telegram bot. It also uses the NetSupport RAT tool to remotely control the infected computer. Researchers warn that no legitimate CAPTCHA or routine website verification should require users to open Windows Run and paste a command.