Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
Summary
Hackers are leveraging custom GPTs within ChatGPT to impersonate legitimate products and trick users into running malicious PowerShell commands. These attacks, dubbed 'ClickFix,' exploit the personalization features of ChatGPT to create convincing lures.
IFF Assessment
FOE
This article describes a new attack vector that utilizes AI, posing a threat to defenders by enabling more sophisticated social engineering tactics.
Defender Context
Defenders should be aware of emerging attack vectors that use generative AI tools like custom GPTs for social engineering. Vigilance against phishing and social engineering attempts that may appear more sophisticated or personalized is crucial, as attackers can now more easily craft convincing impersonations.