It was only a matter of time before hackers started leveraging the immense popularity of ChatGPT to push malware (opens in new tab) and steal sensitive personal data - and several security companies have now spotted this happening.
For the uninitiated, OpenAI's ChatGPT is an AI-powered chatbot whose popularity has skyrocketed in recent months.
The novelty of its output, plus Microsoft's eagerness to invest in the technology, made it the most sought-after technology online, hitting more than 100 million users in just two months (November 2022 to January 2023), according to BleepingComputer (opens in new tab).
The demand, inevitably, led to the service's monetization. Those who want uninterrupted access to the platform can get it for $20 a month.
Per BleepingComputer, cybersecurity pros have found different hacker campaigns promising free access. These are, obviously, cases of "if it sounds too good to be true, it probably is," and you should be wary of them.
In one such example, threat actors were pushing Redline, a known infostealer capable of grabbing passwords and credit card data stored in web browsers, taking screenshots, exfiltrating files, and more.
To deliver the malware, they created a fake website promoting uninterrupted access to ChatGPT, and even created a Facebook page to promote the website. Other hackers tried to distribute the Aurora stealer.
> ChatGPT already feared to be behind multiple cyberattacks (opens in new tab)
> Hackers could exploit ChatGPT to attack networks (opens in new tab)
> Check out the best firewalls right now (opens in new tab)
There are also fake ChatGPT apps being distributed via Google Play and other third-party Android app stores. It goes without saying that users wouldn’t be getting access to the chatbot, only unknown forms of malware. So far, there are dozens of such apps: researchers from Cyble found more than 50.
For the avoidance of doubt, the only way to access ChatGPT is via the official website - https://chat.openai.com/ - and OpenAI’s APIs. All other "alternatives" aren't credible, and could impact your smartphone's security and your privacy.
- Here's our rundown of the best endpoint protection (opens in new tab) right now
Via: BleepingComputer (opens in new tab)