MediumNewsLLM-specific
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
- Published
- Record updated
Summary
A ClickFix campaign used two ChatGPT Custom GPTs to direct victims to a Google Sites page, where they were told to run a PowerShell command that downloaded a malicious MSI installer. Huntress reports at least 40 users were infected, at least two of them linked to a Custom GPT, and OpenAI removed the first Custom GPT on September 25 before a second was found on September 27.
Related items
- InfoOpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSame vendor · SecurityWeek
- Info‘Pure insanity’: Mathematicians will need years to make sense of OpenAI’s latest dropSame vendor · The Verge (AI)
- InfoOpenAI reports three new incidents of misalignmentSame vendor · CSO Online
- InfoA new feature for my blog, built using my voiceSame vendor · Simon Willison's Weblog
- InfoOpenAI's revenue scare, Delta earnings, what investors think of a Starbucks-Chipotle deal and more in Morning SquawkSame vendor · CNBC Technology