iSport News

Security experts have raised alarms over a sophisticated malware campaign exploiting Google search results to compromise computers remotely. The attack begins innocuously enough, with users searching for ChatGPT on Google, but the consequences are far-reaching, enabling attackers to seize full control of infected devices.

Unlike traditional malware distribution methods, this campaign leverages legitimate services to deceive victims. Among the sponsored links appearing in search results, one directs users to chatgpt.com, the official domain of OpenAI. However, this seemingly trustworthy link actually leads to a malicious customized GPT named “Plus 5.6”, crafted by the attackers to masquerade as a genuine version of the chatbot.

How the Scam Operates Using Trusted Platforms

According to cybersecurity firm Huntress, this malware operation stands out due to the attackers’ use of reputable platforms to build credibility. Victims who click the sponsored ad are directed through a Cloudflare CAPTCHA, adding an illusion of legitimacy. Following this, the malware silently installs a Trojan horse on the victim’s system, granting the hackers remote access.

This Trojan carries alarming capabilities: it can navigate through files, activate the device’s camera and microphone without consent, and effectively take full control of the computer. The deceptive use of official domains and common web security measures makes this campaign particularly dangerous, as it exploits users’ trust in familiar brands and services.

As a result, internet users searching for AI tools like ChatGPT must exercise heightened caution, since even official-looking search results may conceal threats designed to infiltrate their devices through sophisticated social engineering tactics.

News iSport