Illusory Bot Framework: Hijacks Social Media Passwords
Illusory Bot Framework: Hijacks Social Media Passwords
A malicious Chrome extension using ChatGPT’s name is being used to steal users’ Facebook logins for malicious advertising.
MUO VIDEO OF THE DAY
SCROLL TO CONTINUE WITH CONTENT
Disclaimer: This post includes affiliate links
If you click on a link and make a purchase, I may receive a commission at no extra cost to you.
A Fake ChatGPT Extension Is Targeting Facebook Users
Facebook and Chrome users are being targeted by a malicious browser extension using the well-known name of the AI-powered chatbot ChatGPT .
On March 8, 2023, Guardio Labs researcher Nati Tal stated in a Medium blog post that “a Chrome Extension propelling quick access to fake ChatGPT functionality was found to be hijacking Facebook accounts and installing hidden account backdoors.”
In the Medium blog post , Tal also noted the use of “a malevolent silently forced Facebook app ‘backdoor’ giving the threat actors super-admin permissions.” The extension can also harvest victims’ browser cookies.
Guardio took to Twitter to warn readers of the malicious campaign.
The phony browser extension, named “Quick access to Chat GPT”, can hack high-profile Facebook accounts to create “hijacked Facebook bot accounts”. The threat actor is then “publishing more sponsored posts and other social activities on behalf of its victim’s profiles and spending business account money credits.”
It was also speculated in the blog post that, once the attacker has accessed your data, they will “probably sell it to the highest bidder as usual.”
Thousands of Facebook Accounts May Have Been Compromised
In this malicious campaign, thousands of Facebook accounts may have been successfully hijacked. In the aforementioned blog post, it was stated that there are “more than 2000 users installing this extension on a daily basis since its first appearance on 03/03/2023.”
On top of this, Tal wrote that each one of the individuals installing the add-on “gets his Facebook account stolen and probably this is not the only damage,” suggesting that other consequences may arise from the extension’s presence.
The Malicious App Has Been Removed from Chrome
Though thousands have downloaded this phony browser extension, it has now been taken down from the Google Chrome Store, preventing further attacks via Chrome-based downloads. It is not yet known exactly how many people have been affected by this campaign, but the number of installations is a definite concern.
ChatGPT’s Name Is Consistently Used by Scammers
Since ChatGPT’s rise to fame, its name has been repeatedly used by cybercriminals to gain the trust of potential victims. Whether its phony ChatGPT-related tokens, or malicious Chat GPT-branded extensions, the popularity of this AI-powered chatbot is undoubtedly being exploited by malicious actors to steal data and money.
SCROLL TO CONTINUE WITH CONTENT
Also read:
- [New] 2024 Approved Enhancing Engagement 30 Outstanding Video Concepts
- [Updated] A Beginner’s Pathway Building a Simple YouTube Signup for 2024
- [Updated] Crafting Compelling FreeFire Vids with Strategy Guide for 2024
- [Updated] Revolutionize Your Social Media Experience with Premier Tools for 2024
- Apple ID is Greyed Out On iPhone 15 Pro Max How to Bypass?
- Beyond Conventional Wisdom: Discovering Next-Gen Careers Shaped by Artificial Intelligence | ZDNet's Deep Dive
- Beyond Numbers: Understanding the Complexities of Staff Changes in Leading Technology Firms
- Boost Your Income on Reddit with These 13 Strategies for 2024
- Effective Networking Strategies for Introverts Unveiled by Experts at ZDNet
- Embracing Innovation: How AI Transforms Developers Into Visionary Business Leaders - Insights From ZDNet
- Emerging Roles in Software Management with the Advent of Generative AI | Insights on ZDNet
- Emerging Software Supervision in the Age of Generative AI: Understanding New Leadership Positions
- Face to Face Fun: Uncovering the Coolest Mobile Dual Players (Top 15)
- From Kitchen to Code: Your Roadmap for Switching Careers Into Technology with ZDNet Insights
- Graphics Correction: Step-by-Step Windows 11
- In 2024, How to Track Xiaomi Redmi K70 Pro Location without Installing Software? | Dr.fone
- Mastering AI Skills Without Stress: Insights by ZDNet
- Overcoming the Challenge of Complex AI Systems for Non-Techies | Diverse Education Strategies Revealed by ZDNET
- The Ultimate Guide to Tweaking Windows Metadata Dates
- Title: Illusory Bot Framework: Hijacks Social Media Passwords
- Author: Brian
- Created at : 2024-12-26 21:03:03
- Updated at : 2024-12-27 21:51:57
- Link: https://tech-savvy.techidaily.com/illusory-bot-framework-hijacks-social-media-passwords/
- License: This work is licensed under CC BY-NC-SA 4.0.