Hackers Abuse ChatGPT, Claude, and Grok Pages to Spread FakeAgent, AMOS Malware
Threat actors are exploiting trusted AI platforms including Claude Artifacts, ChatGPT, and Grok shared pages to distribute malware targeting both Windows and macOS users. On Windows, sponsored Bing ads lead victims to a legitimate-looking Claude Artifact that redirects them to a fake Claude Desktop installer, which deploys SectopRAT via DLL side-loading. On macOS, attackers use fake Apple Support pages on Claude Share and spoofed disk-cleanup guides in ChatGPT and Grok search results to trick users into pasting malicious Terminal commands. These commands deploy multi-stage loaders including MacSync and AMOS, which steal browser credentials, Keychain data, SSH keys, and cryptocurrency wallet information. Security researchers at Huntress confirmed infections across multiple organizations, rating the threat as high severity due to the abuse of user trust in reputable AI-sharing infrastructure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in