logo

Hackers Attacking Android Users With Fake ChatGPT Invites to Deploy Malware

ID: e0d6a10d-f6f1-5ef5-b9f6-1acaaa5d8ef9

STIX ID: report--e0d6a10d-f6f1-5ef5-b9f6-1acaaa5d8ef9

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A phishing campaign distributing malicious Android APKs via legitimate-looking Firebase App Distribution invitations poses as beta ChatGPT and Meta advertising tools; installed apps (e.g., com.OpenAIGPTAds, com.opengpt.ads, com.meta.adsmanager) present fake Facebook login screens to steal credentials and enable business/ads account takeover. SpiderLabs identified supporting malicious domains (for example: thcsmyxa-nd.com, moitasec.com, tourmini.site, ocngongiare.com, disanviet.homes, itrekker.space) and warns users to avoid sideloading apps and administrators to block the listed domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.