Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Summary

Malicious actors are leveraging custom ChatGPTs, promoted through sponsored Google ads, to lure users to phishing sites. These sites then employ ClickFix attacks to deploy Remote Access Trojan (RAT) malware onto unsuspecting users' systems.

IFF Assessment

FOE

This article highlights a new attack vector that exploits user trust in AI tools to deliver malware, posing a direct threat to defenders.

Defender Context

Defenders should be aware of the emerging threat of AI-generated lures and malicious content. Users are increasingly susceptible to attacks disguised as legitimate AI interactions, necessitating enhanced user awareness training and robust endpoint protection capable of detecting novel malware delivery techniques.

Read Full Story →