• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
fake chatgpt chrome extension hijacking facebook accounts for malicious advertising

Fake ChatGPT Chrome Extension Hijacking Facebook Accounts for Malicious Advertising

You are here: Home / General Cyber Security News / Fake ChatGPT Chrome Extension Hijacking Facebook Accounts for Malicious Advertising
March 13, 2023

A fake ChatGPT-branded Chrome browser extension has been observed to arrive with capabilities to hijack Fb accounts and develop rogue admin accounts, highlighting 1 of the different methods cyber criminals are employing to distribute malware.

“By hijacking superior-profile Facebook enterprise accounts, the risk actor generates an elite military of Facebook bots and a destructive paid out media apparatus,” Guardio Labs researcher Nati Tal reported in a technological report.

“This allows it to drive Fb paid ads at the cost of its victims in a self-propagating worm-like manner.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The “Swift accessibility to Chat GPT” extension, which is mentioned to have attracted 2,000 installations per working day because March 3, 2023, has considering that been pulled by Google from the Chrome Web Retailer as of March 9, 2023.

The browser insert-on is promoted through Facebook-sponsored posts, and although it provides the capacity to link to the ChatGPT provider, it truly is also engineered to surreptitiously harvest cookies and Fb account knowledge utilizing an presently energetic, authenticated session.

This is obtained by building use of two bogus Fb purposes – portal and msg_kig – to manage backdoor obtain and obtain whole control of the concentrate on profiles. The course of action of incorporating the apps to the Fb accounts is thoroughly automated.

The hijacked Facebook business enterprise accounts are then employed to publicize the malware, therefore properly growing its army of Fb bots.

ChatGPT Chrome Extension

The growth comes as danger actors are capitalizing on the substantial attractiveness of OpenAI’s ChatGPT considering the fact that its release late previous year to build fake variations of the artificial intelligence chatbot and trick unsuspecting consumers into installing them.

Very last thirty day period, Cyble unveiled a social engineering marketing campaign that relied on an unofficial ChatGPT social media web site to direct customers to destructive domains that obtain information and facts stealers, this kind of as RedLine, Lumma, and Aurora.

WEBINARDiscover the Concealed Dangers of Third-Party SaaS Apps

Are you conscious of the challenges involved with 3rd-party app accessibility to your firm’s SaaS applications? Be a part of our webinar to master about the sorts of permissions getting granted and how to lessen risk.

RESERVE YOUR SEAT

Also spotted are faux ChatGPT applications distributed by way of the Google Participate in Retail store and other 3rd-party Android app outlets to drive SpyNote malware onto people’s gadgets.

“Regretably, the success of the viral AI device has also attracted the consideration of fraudsters who use the technology to carry out highly refined expense scams towards unwary internet customers,” Bitdefender disclosed previous week.

Identified this posting fascinating? Comply with us on Twitter  and LinkedIn to browse much more distinctive articles we put up.


Some elements of this write-up are sourced from:
thehackernews.com

Previous Post: «Cyber Security News How to Apply NIST Principles to SaaS in 2023
Next Post: An in-depth analysis of the Microsoft 365 threat landscape an in depth analysis of the microsoft 365 threat landscape»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
  • Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts

Copyright © TheCyberSecurity.News, All Rights Reserved.