Fake ChatGPT Invites Target Android Users With Malware
ID: c90a3d7e-3cb0-56ef-85cd-468759dfed1b
STIX ID: report--c90a3d7e-3cb0-56ef-85cd-468759dfed1b
Feed Name: GBHackers
Threat Score
Threat actors are abusing Firebase App Distribution to push fake Android ChatGPT and Meta advertising apps via invitation-style emails; once sideloaded the apps present Facebook login webviews that harvest credentials and 2FA/business verification tokens, enabling account and ad-account takeover. Organizations are advised to enforce MFA, restrict sideloading, tune email gateways to flag Firebase links, and obtain apps only from official stores or verified channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
