A real ChatGPT page is being used to trick people into installing malware
The dangerous part only appears after ChatGPT has already earned your trust.
Attackers have exploited the popular AI chatbot ChatGPT to distribute malware, tricking users into installing malicious software. The perpetrators created a fake ChatGPT model named "Plus 5.6" on the authentic ChatGPT website. This deceptive model led users to a simulated security check that ultimately prompted them to run a harmful Windows command.
The command had the potential to access sensitive data, including files, the screen, the webcam, and the microphone. This sophisticated attack highlights the growing challenge of identifying suspicious downloads when they originate from trusted websites. Researchers at Huntress, as reported by TechRadar, uncovered this malware campaign that leveraged ChatGPT's Custom GPT feature to create the convincing bot "Plus 5.6."
The attackers chose this name to mimic an official OpenAI model, as Custom GPTs are hosted on ChatGPT.com, making the link appear legitimate in users' browsers.
Written by urgent.news from Android Authority's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.