Security Researchers Discover Fake ChatGPT Ads Tricking Users Into Downloading Malware

Security Researchers Discover Fake ChatGPT Ads Tricking Users Into Downloading Malware

  • Tags
  • Tech News
  • Cybersecurity
  • ChatGPT
  • Malware
  • Google Ads

Security researchers have uncovered a sophisticated malicious advertising campaign exploiting Google Search to distribute dangerous Windows malware. The operation leverages sponsored advertisements mimicking ChatGPT and Custom GPT platforms to trap unsuspecting users in what cybersecurity experts call 'ClickFix' attacks.

How the Fake ChatGPT Ad Campaign Operates

According to findings from the AI security firm Island, threat actors have deployed hundreds of sponsored Google ads that surface when users search for keywords like 'chatgpt'. Initially, these ads may direct users to legitimate web instances of OpenAI's platform. However, once users attempt to interact with the service by typing a prompt, a deceptive notification triggers, claiming high traffic volumes and redirecting the victim to a 'backup domain'.

This backup domain leads to a meticulously crafted replica of ChatGPT featuring a fake Cloudflare security verification screen. Instead of passing a standard CAPTCHA, the prompt instructs users to perform actions utilizing built-in Windows diagnostic tools, executing hidden commands that download and run malicious payloads.

The Mechanics of ClickFix and NetSupport RAT

ClickFix attacks rely heavily on social engineering, coercing users into executing commands manually through tools like PowerShell or the Windows Run dialog. Once the malicious script is executed, it establishes persistence on the host machine, allowing it to survive system reboots.

Furthermore, the deployed malware integrates remote access trojans (RATs)—specifically leveraging tools like NetSupport RAT—to grant threat actors remote control over infected computers. Stolen data is funneled back to the attackers via automated Telegram bots, posing a severe risk to personal and professional data privacy.

Protecting Yourself Against Malvertising and Scams

As malvertising tactics grow increasingly sophisticated, internet users must exercise extreme caution. Security experts recommend the following preventive measures:

  • Direct Navigation: Avoid using search engines to find popular AI tools; instead, directly type official URLs such as chatgpt.com into your browser address bar.
  • Recognize Red Flags: Official web services will never direct you to external 'backup domains' due to traffic nor ask you to open the Windows Run dialog or PowerShell to complete a verification check.
  • Use Ad Blockers and Antivirus: Employ reputable ad-blocking extensions to filter out sponsored search results and ensure up-to-date, robust antivirus software is actively running on your devices.

Security firms continue to monitor these emerging threats, emphasizing the vital need for vigilance in navigating modern digital landscapes.

Comments (0)

Sign in to join the conversation.Sign in

Loading comments...