'Quick access to ChatGPT' Browser Extension Causes a Stir

computer malware theft

Thousands of Facebook accounts, including business accounts, may have been compromised by a sophisticated fake Google Chrome ChatGPT browser extension that was available on the official Chrome Store until earlier this week.

The "Quick access to Chat GPT" extension was analyzed by security firm Guardio, which discovered that it was actually delivering the quick access it promised to the hugely popular AI chatbot. However, the extension also harvested a range of browser information and cookies, installed a backdoor and stole all authorized active sessions. The malware author was given super-admin permissions to the user's Facebook account. Threat actors have been leveraging public interest in ChatGPT to distribute malware in a variety of ways, including setting up a fake landing page for users to download the Trojan Fobo, and using ChatGPT themed phishing emails and fake apps to spread Windows and Android malware.

Guardio's analysis showed that the malicious extension harvested a complete list of all the cookies stored in the user's browser, including security and session tokens to Google, Twitter, and YouTube, and to any other active services. The extension also accessed the Meta Graph API for developers, giving it the ability to harvest all data associated with the user's Facebook account and take a variety of actions on the user's behalf.

In addition, a component in the extension code allowed for hijacking of the user's Facebook account by registering a rogue app on the user's account, essentially giving the threat actor full admin mode on the victim's Facebook account without having to harvest passwords or bypass Facebook's two-factor authentication.

The extension targeted Facebook business accounts for a "bot army," harvesting all information pertaining to that account, including currently active promotions, credit balance, currency, minimum billing threshold, and whether the account might have a credit facility associated with it. This is one example of the many ways in which threat actors have been targeting businesses and organizations to obtain access to their sensitive data, which can be used for further attacks or sold on the dark web.

March 13, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.