Hackers Attacking Android Users With Fake ChatGPT Invites to Deploy Malware
ID: e0d6a10d-f6f1-5ef5-b9f6-1acaaa5d8ef9
STIX ID: report--e0d6a10d-f6f1-5ef5-b9f6-1acaaa5d8ef9
Feed Name: cybersecurityNews.com
A phishing campaign distributing malicious Android APKs via legitimate-looking Firebase App Distribution invitations poses as beta ChatGPT and Meta advertising tools; installed apps (e.g., com.OpenAIGPTAds, com.opengpt.ads, com.meta.adsmanager) present fake Facebook login screens to steal credentials and enable business/ads account takeover. SpiderLabs identified supporting malicious domains (for example: thcsmyxa-nd.com, moitasec.com, tourmini.site, ocngongiare.com, disanviet.homes, itrekker.space) and warns users to avoid sideloading apps and administrators to block the listed domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
