top of page

Warning: Cybercriminals posing as ChatGPT distribute malware through a series of compromised Facebook accounts

The irresistible allure of ChatGPT artificial intelligence is becoming prime bait for cybercriminal groups to exploit. Security researchers have recently exposed a sophisticated campaign in which attackers hijack numerous Facebook pages and accounts with large followings for the purpose of phishing and distributing malware to users.

The "name-changing" tactic of Facebook accounts with hundreds of thousands of followers

A recent investigation exposed the hackers' actions targeting 13 compromised Facebook pages and accounts. Alarmingly, these accounts collectively possess more than 500,000 active followers.

To successfully carry out their scheme, immediately after hacking a Facebook account or page, the attackers promptly proceed to change all profile information. They set the new username to “ChatGPT OpenAI” and use the official image of this tool as their profile picture. By leveraging the existing trust and engagement of these hijacked accounts, the hackers begin deploying malicious ad campaigns to trap followers.

They set the new username to “ChatGPT OpenAI” and use the official image of this tool as their profile picture.
They set the new username to “ChatGPT OpenAI” and use the official image of this tool as their profile picture.

The scenario of luring users to download malware via advertisements

After donning the perfect disguise, the criminal group uses these accounts to run Facebook ads, heavily promoting a tool dubbed the “latest version of ChatGPT, GPT-V4”.

In the promotional posts, users are provided with a download link that appears completely harmless. To establish maximum trust and convince gullible individuals, the ads are designed very professionally, containing all the necessary information, accompanied by both a password and a download link to increase credibility. The perpetrators used various intermediary channels to host and distribute this malicious file, including:

  • Trello boards

  • Google Drive

  • Numerous separate personal websites

In addition, researchers discovered about 25 different websites impersonating OpenAI's official website to profit from the victims. Notably, the majority of the hacked accounts repeatedly used the exact same specific video to attract and retain viewers. This matching pattern indicates that an individual or an organized cybercriminal group is behind this entire malware distribution campaign via Facebook ads.

The perpetrators used various intermediary channels to host and distribute this malicious file.
The perpetrators used various intermediary channels to host and distribute this malicious file.

The danger of malware and the most affected countries

When users fall into the trap and download the file to their devices, they inadvertently invite data-stealing malware into their systems. This type of malware is equipped with persistent self-maintenance mechanisms, allowing it to hide and take deep root in the system to progressively gain deeper control over the device. Furthermore, the originally hijacked accounts themselves are also capable of stealing confidential and sensitive information from the victims.

According to a report by CloudSEK security experts sent to Cyber Security News, this wave of attacks is occurring at a breakneck pace. The oldest recorded hacked case was a page with over 23,000 followers. However, hackers do not spare new accounts; even accounts created just a few days prior have fallen into their crosshairs.

Although the hijacked Facebook accounts originate from various countries, the majority of their administrators are concentrated in:

  • Vietnam

  • Philippines

  • Brazil

  • Pakistan

  • Mexico

Among these, the number of compromised accounts recorded the most prominent and aggressive spike in Vietnam and the Philippines compared to the other regions.

Advice from security experts

In the face of online scams becoming increasingly sophisticated and continuously exploiting trendy tech trends, cybersecurity experts strongly advise: Users need to elevate their vigilance to the maximum, carefully verify the source of information, and absolutely refrain from clicking on suspicious links or downloading unfamiliar files on social media.

The scam campaign masquerading as ChatGPT once again sounds the alarm on information security. Staying alert to software labeled "free" or "latest" promoted through unofficial channels is the best shield to protect your personal data.

Reference: Cyber Security News

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page