Fake ChatGPT Invitations Target Android Users In New Malware Campaign

Cybercriminals are constantly finding new ways to trick people into downloading harmful software. Following a recent wave of phishing attacks aimed at iOS users, hackers have shifted their focus to a new target.

A newly discovered malware campaign is now setting its sights on Android users across the globe. This attack uses the immense popularity of artificial intelligence tools and social media platforms to lure in unsuspecting victims.

By offering fake beta testing invitations for ChatGPT and Meta advertising applications, attackers are successfully tricking users into installing dangerous malware on their mobile devices.

How The Malware Campaign Works

Attackers are abusing Firebase App Distribution to spread their malicious applications. Firebase is a legitimate tool provided by Google that developers use to send pre-release versions of their apps to trusted testers.

Because it is an official Google service, the invitation emails are sent directly from the address “firebase-noreply@google.com.”

This official sender address is the key to the entire scam. When a user sees an email from Google, they are highly likely to trust it and click the links without a second thought.

Fake ChatGPT Invites Target (Source: SpiderLabs)
Fake ChatGPT Invites Target (Source: SpiderLabs)

Defending Against The Threat and Identifying Compromise

Protecting yourself from this type of attack requires a mix of caution and awareness. The most important step is to be highly skeptical of unsolicited invitations to test new applications, even if they appear to come from a trusted company.

Real developers rarely send random users beta-testing invites out of the blue. If you receive an unexpected email offering early access to a popular app, it is safest to ignore it entirely.

You should only download applications from the official Google Play Store, where apps undergo basic security scans before being published.

Fake ChatGPT Invites Target (Source: SpiderLabs)
Fake ChatGPT Invites Target (Source: SpiderLabs)

Security teams and network administrators can also take steps to block this specific threat. By monitoring network traffic and device installations, organizations can stop these malicious apps from compromising corporate data.

Spider Labs Tracking specific markers, known as Indicators of Compromise (IOCs), is an effective way to detect whether an attack is underway.

Indicator TypeDetails
Application Package Namecom.OpenAIGPTAds
Application Package Namecom.opengpt.ads
Application Package Namecom.meta.adsmanager
Malicious Email Domainthcsmyxa-nd[.]com
Malicious Email Domainmoitasec[.]com

To help identify and block this malware campaign, security researchers have published a list of known IOCs associated with the attacks.

These include the specific package names of the fake applications and the malicious email domains used by the attackers.

Blocking these domains at the network level can prevent phishing emails from reaching users. The table below lists the specific package names and malicious domains associated with this fake ChatGPT and Meta app campaign.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories