Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Summary
Malicious actors are leveraging custom ChatGPTs, promoted through sponsored Google ads, to lure users to phishing sites. These sites then employ ClickFix attacks to deploy Remote Access Trojan (RAT) malware onto unsuspecting users' systems.
IFF Assessment
FOE
This article highlights a new attack vector that exploits user trust in AI tools to deliver malware, posing a direct threat to defenders.
Defender Context
Defenders should be aware of the emerging threat of AI-generated lures and malicious content. Users are increasingly susceptible to attacks disguised as legitimate AI interactions, necessitating enhanced user awareness training and robust endpoint protection capable of detecting novel malware delivery techniques.