Malicious Custom GPTs steer users into remote access malware
Daily Cyber News: Malicious Custom GPTs steer users into remote access malware
Users searching for AI services can be manipulated into installing remote access malware themselves. In this campaign, attackers used sponsored search results, a malicious Custom GPT, a fake service notice, and a counterfeit CAPTCHA. Victims were then instructed to paste an obfuscated PowerShell command.
Key context: The attack borrows trust from familiar AI and CAPTCHA experiences while shifting the final execution step to the user.
Additional detail: For leaders, a legitimate and trusted platform can still host the first step of a social-engineering chain.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, malware, Malicious Custom GPTs, Malicious, Custom, GPTs, steer, users.