Добавить новость
News in English
Новости сегодня

Новости от TheMoneytizer

Fake ChatGPT Chrome extension hacked Facebook accounts to spread ISIS propaganda

A fraudulent Chrome browser extension masquerading as OpenAI's ChatGPT tool was used by hackers this month to hijack Facebook accounts.

The extension, which was designed to look nearly identical to OpenAI's legitimate ChatGPT browser add-on, was downloaded more than 9,000 times before eventually being taken down by Google.

The malicious extension operated the same as the real extension, which offered ChatGPT responses alongside search engine results, but also included extra lines of code that attempted to steal session cookies used by Facebook.

Once downloaded, the hackers are able to log in and take total control of a victim's Facebook account using the stolen cookies.

Uploaded to the Chrome store on February 14, the add-on, as first reported by cybersecurity firm Guardio Labs, began appearing in Google search advertisements exactly one month later.

One victim of the attack, according to Guardio Labs' report, even had their Facebook business account used to promote ISIS propaganda.

"The misuse of ChatGPT’s brand and popularity just keeps on rising, used not only for Facebook account harvesting and not only with malicious fake Extensions for Chrome," wrote Nati Tal, head of Guardio Labs.

"Major services offered by Facebook, Google, and other big names are under continuous attack and abuse, while at the end of it all—the ones being mostly hit here are us, the users."

In a statement to Bleeping Computer on Wednesday, Google confirmed that it removed the extension after being alerted to its presence on the Chrome Web Store.

"We don’t allow ads on our platform that use malicious techniques such as phishing," a Google representative said. "We’ve reviewed the ads in question and taken appropriate action. The extension is no longer available from the Chrome Web Store."

The unknown threat actors behind the malicious add-on carried out a similar attack in the past.

Guardio Labs found that the extension was communicating with the same infrastructure as another fake ChatGPT add-on that was downloaded more than 4,000 times before being removed earlier this month.

"This time, threat actors didn’t have to work hard on the look and feel of this malicious ChatGPT-themed extension—they just forked and edited a well-known open-source project that does exactly that," Guardio Labs reported. "From zero to 'hero' in probably less than 2 minutes."

Sign up to receive the Daily Dot’s Internet Insider newsletter for urgent news from the frontline of online.

The post Fake ChatGPT Chrome extension hacked Facebook accounts to spread ISIS propaganda appeared first on The Daily Dot.

Читайте на сайте


Smi24.net — ежеминутные новости с ежедневным архивом. Только у нас — все главные новости дня без политической цензуры. Абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Мы не навязываем Вам своё видение, мы даём Вам срез событий дня без цензуры и без купюр. Новости, какие они есть —онлайн с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии. Smi24.net — живые новости в живом эфире! Быстрый поиск от Smi24.net — это не только возможность первым узнать, но и преимущество сообщить срочные новости мгновенно на любом языке мира и быть услышанным тут же. В любую минуту Вы можете добавить свою новость - здесь.




Новости от наших партнёров в Вашем городе

Ria.city
Музыкальные новости
Новости России
Экология в России и мире
Спорт в России и мире
Moscow.media






Топ новостей на этот час

Rss.plus





СМИ24.net — правдивые новости, непрерывно 24/7 на русском языке с ежеминутным обновлением *