ChatGPT-Related Malicious URLs on the Rise

The number of new registrations and squatting domains associated with ChatGPT increased by 910% monthly from November 2022 to early April 2023.

The findings shared today by Unit 42 of Palo Alto Networks also noted a 17,818% increase in related squatting domains from DNS security logs over the same time frame.

A new advisory by Peng Peng, Zhanhao Chen, and Lucas Hu states, “We detected up to 118 ChatGPT-related malicious URLs per day captured from traffic seen by advanced URL filtering systems.” It is written.

Among the trends the researchers observed were multiple phishing URLs attempting to masquerade as official OpenAI websites.

“Usually, scammers create fake websites that look a lot like the official ChatGPT website to trick users into downloading malware or sharing sensitive information,” explained Unit 42. doing.

“Additionally, scammers may use ChatGPT-related social engineering to commit identity theft and financial fraud.”

You can read more about ChatGPT-enabled attacks here: ChatGPT Creates Polymorphic Malware

Palo Alto Networks also observed some scammers exploiting the growing popularity of OpenAI for cryptocurrency scams.

However, some malicious websites do take advantage of the official ChatGPT API made available by OpenAI in March.

“Given the fact that ChatGPT is not accessible in certain countries or regions, websites created with these automated tools or APIs are likely to attract a significant number of users from these regions.

“This also provides an opportunity for attackers to monetize ChatGPT by proxying the service.”

According to the team, these tools are showing growth trends, as well as the general increase in registered and squatting domains associated with ChatGPT.

“To stay safe, ChatGPT users should be aware of suspicious emails and links related to ChatGPT,” reads the advisory. “Furthermore, the use of mimic chatbots poses additional security risks. Users should always access her ChatGPT through her official OpenAI website.”

Unit 42’s advisory comes weeks after a ChatGPT vulnerability allegedly leaked some customers’ payment-related information.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *