logo

How Threat Actors are Exploiting ChatGPT's Popularity to Spread Malware via Compromised Facebook Accounts Putting Over 500,000 People at Risk

ID: ae1575ff-de87-5052-8627-cd4b66424d04

STIX ID: report--ae1575ff-de87-5052-8627-cd4b66424d04

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2023-03-27

Date Updated: 2026-04-27

...
...

This CloudSEK research details an active campaign in which threat actors hijack Facebook pages (13 pages totaling ~500K followers) and run ads that link to malicious downloads posing as ChatGPT/GPT-4; the distributed binary is a stealer that exfiltrates PII and payment information, uses legitimate hosting services (Trello, Google Drive, individual domains) to evade detection, and shows indicators such as Trello boards, specific malicious domains, and Vietnamese-language artifacts suggesting actor origins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.