ChatGPT boom drives surge in AI-powered malware targeting Facebook business accounts

2023-03-14 05:57:43
关注

The use of artificial intelligence to spread malware is increasing month-by-month as platforms like YouTube and Facebook are used to propagate malicious links via AI generated content and a fake ChatGPT extension. While the rise of generative AI chatbots like ChatGPT was always likely to be accompanied by a spike in cybercrime, social media sites should be more proactive in policing their platforms for harmful content as hackers become more advanced, researchers warn. 

ChatGPT and AI used to lure victims into infostealing scams. (Photo by Chrispictures/Shutterstock)

Both YouTube and Facebook have seen their platforms abused by cybercriminals to target their users. Increasingly these malware campaigns are designed using AI and ChatGPT, making them harder to detect.

“The threat actors are getting so sophisticated that it becomes hard for even well-aware users to distinguish between what’s good and what’s bad,” said Allan Liska CSIRT at security vendor Recorded Future.

AI and ChatGPT used to propagate malware campaigns on YouTube and Facebook

A new report from security company CloudSEK states that since November 2022 there has been a 200%-300% month-on-month increase in videos containing infostealer malware being uploaded to YouTube.

The videos masquerade as step-by-step guides on how to download expensive software like Photoshop, Premiere Pro and Autodesk 3DS Max for free. Links to the malware are concealed in the content’s description, and stealers found in the malicious videos include Vidar RedLine and Racoon.

Often AI-generated videos are being used in the campaigns because footage featuring humans with certain facial features have been found to be more popular, as they are more familiar and trustworthy.

“We have observed that every hour five to 10 ‘crack software’ download videos containing malicious links are uploaded to YouTube,” the report says. “At any given time, if a user searches for a tutorial on how to download a cracked software, these malicious videos will be available.”

In a similar style of attack, cybercriminals are luring in victims using a fake ChatGPT add-on for the Chrome browser. The malicious stealer extension is called “Quick Access to Chat CPT” and is promoted on Facebook sponsored posts, advertising a quick way to access the popular chatbot. Instead it implements a malvertising campaign.

Content from our partners

Addressing ESG to build a better, more sustainable business 

Addressing ESG to build a better, more sustainable business 

Empower finance leaders to become agents of change

Empower finance leaders to become agents of change

Why the fashion industry must leverage tech to unlock supply chain visibility 

Why the fashion industry must leverage tech to unlock supply chain visibility 

The extension gives users access ro ChatGPT’s API, but also harvests huge amounts of information from the browser such as cookies and credentials.

View all newsletters Sign up to our newsletters Data, insights and analysis delivered to you By The Tech Monitor team

How the bogus ChatGPT extension works

Once downloaded, the extension becomes an integral part of the browser, allowing it to send requests to any other service, as if the browser owner themselves were administering the commands. “This is crucial as the browser, in most cases, already has an active and authenticated session with almost all your day-to-day services, e.g. Facebook,” explains a report from security company Guardio.

If the victim has a Facebook business account, it will be taken over completely. “By hijacking high-profile Facebook business accounts, the threat actor creates an elite army of Facebook bots and a malicious paid media apparatus. This allows it to push Facebook paid ads at the expense of its victims in a self-propagating worm-like manner,” continues the report.

“Once the victim opens the extension windows and writes a question to ChatGPT, the query is sent to OpenAI‘s servers to keep you busy – while in the background it immediately triggers the harvest.”

Tech Monitor has contacted YouTube and Facebook for comment.

Cybercriminals using AI and ChatGPT is to be expected, says Liska, but their scams are rapidly increasing in sophistication. “Our advice is always, ‘take a minute to think about what you’re doing. Is that really a ChatGPT application or is it a scam?’,” he says.

But it’s getting harder and harder to identify the fakes, Liska adds. “We’re in a sort of ‘Wild West’ ecosystem where it can be hard to distinguish between what’s illegitimate and what’s real,” he says.

“We need to start holding both software companies and platforms accountable for the bad things that happen on their network, when they allow this kind of malware to propagate on their platform without taking steps to address it.”

Read more: Malware infects more than 14,000 WordPress sites

Topics in this article : Cybersecurity

参考译文
ChatGPT热潮导致针对Facebook商业账户的人工智能恶意软件激增
随着人工智能用于传播恶意软件在YouTube和Facebook等平台上通过AI生成内容和伪造的ChatGPT扩展传播恶意链接的情况逐月上升,研究人员警告称,社交网站应更加积极地对其平台上的有害内容进行监管。虽然生成式AI聊天机器人如ChatGPT的出现很可能会伴随着网络犯罪的激增,但黑客手段越来越先进,平台方应采取更主动的措施。ChatGPT和AI被用来诱骗受害者参与窃取信息的骗局。(照片由Chrispictures/Shutterstock提供)YouTube和Facebook都已遭到网络罪犯的滥用,以针对其用户。这些恶意软件活动越来越多地利用AI和ChatGPT设计,使其更难以被检测到。网络安全公司Recorded Future的安全CSIRT团队成员Allan Liska表示:“威胁行为者变得如此复杂,即使是警惕的用户也很难分辨什么内容是好的,什么内容是坏的。”AI和ChatGPT被用来在YouTube和Facebook上传播恶意软件活动。网络安全公司CloudSEK的一项新报告指出,自2022年11月以来,包含信息窃取型恶意软件的视频上传量每月增长了200%到300%。这些视频伪装成逐步指南,教用户如何免费下载昂贵的软件,如Photoshop、Premiere Pro和Autodesk 3DS Max。恶意链接隐藏在视频描述中,而这些视频中包含的窃取工具包括Vidar RedLine和Racoon。经常使用AI生成的视频是因为包含特定面部特征的人类视频更受欢迎,因为它们看起来更熟悉、更可信。报告称:“我们发现每小时都会上传5到10个包含恶意链接的‘破解软件’下载视频到YouTube。”“在任何时刻,如果用户搜索如何下载破解软件的教程,这些恶意视频就会出现。”在类似的攻击中,网络罪犯使用一个伪造的Chrome浏览器ChatGPT扩展来诱骗受害者。这个恶意窃取扩展程序名为“Quick Access to Chat CPT”,通过Facebook的付费推广帖子进行宣传,声称可以快速访问热门聊天机器人。实际上,它实施的是一种恶意广告活动。内容由我们的合作伙伴提供。应对ESG构建更美好、可持续发展的企业 赋能财务领袖成为变革的推动者 时尚产业为何必须利用技术解锁供应链可见性 该扩展程序会为用户提供访问ChatGPT API的功能,但同时也会从浏览器中窃取大量信息,如cookie和凭据。 订阅我们的所有新闻通讯 数据、洞察和分析即时送达 由Tech Monitor团队提供 在这里注册 这个虚假的ChatGPT扩展程序一旦被下载,就会成为浏览器的一部分,允许它像浏览器所有者亲自操作一样向任何其他服务发送请求。网络安全公司Guardio的一份报告解释道:“这是关键的,因为浏览器在大多数情况下,已经与你日常使用的所有服务建立了活跃且经过身份验证的会话,例如Facebook。”如果受害者拥有Facebook商业账户,该账户将被完全接管。报告继续指出:“通过劫持高影响力的Facebook商业账户,威胁行为者创建了一支精英级的Facebook机器人军队和恶意付费媒体体系。这使他们可以以牺牲受害者为代价,以自我传播的蠕虫式方式进行Facebook付费广告的传播。”“一旦受害者打开扩展窗口并向ChatGPT提问,查询会被发送到OpenAI的服务器上,以分散你的注意力——而与此同时,它在后台立即触发信息窃取行为。”Tech Monitor已联系YouTube和Facebook征求评论。Liska表示,网络罪犯使用AI和ChatGPT是意料之中的事,但他们的骗局正在迅速变得更加复杂。“我们的建议始终是,‘花一分钟思考一下你正在做的事情,那是真正的ChatGPT应用,还是一场骗局?’”他说道。但识别虚假信息变得越来越困难,Liska补充说:“我们现在处在一个类似‘西部荒野’的生态系统中,在这里,很难区分什么内容是非法的,什么内容是真实的。”“我们需要开始要求软件公司和平台对其网络上发生的所有不良事件负责,当它们允许此类恶意软件在平台上传播却不采取措施进行干预时。”阅读更多:恶意软件已感染超过14,000个WordPress网站 本文主题:网络安全
您觉得本篇内容如何
评分

评论

您需要登录才可以回复|注册

提交评论

广告

techmonitor

这家伙很懒,什么描述也没留下

关注

点击进入下一篇

ChatGPT引发AI人才战:年薪百万只是起点

提取码
复制提取码
点击跳转至百度网盘