Hackers exploit ChatGPT custom GPTs in ClickFix attacks
Summary
Hackers are now using customized versions of ChatGPT in ClickFix attacks, exploiting AI chatbots to enhance their social engineering tactics for more convincing deception. This trend is part of a broader movement where cybercriminals are integrating mainstream AI technologies, repurposing them to support malware distribution campaigns in an increasingly sophisticated manner.
Analysis
ChatGPT: ChatGPT is OpenAI's conversational AI platform built on large language models that supports user-created custom instances known as Custom GPTs for specialized tasks and interactions. The service enables tailored AI behaviors through natural language instructions without requiring technical expertise. In the reported incident, malicious actors are misusing these Custom GPTs to generate or automate components of ClickFix attacks that deceive users into running harmful code. AI Abuse: Custom AI assistants are being repurposed by threat actors to support malware distribution campaigns. Cybersecurity: Cybercriminals are integrating mainstream AI chatbots into social engineering tactics to create more convincing attack flows.
Categories
aitech