TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

Hackers Exploit ChatGPT to Distribute Malware

Akinola Ajibola by Akinola Ajibola
December 16, 2025
in Artificial Intelligence, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • By now, everyone should be aware that not everything AI tells you can be trusted.
  • Threat actors are now using paid search ads on Google to share and promote conversations with ChatGPT and Grok that seem to offer tech support instructions...
  • Large language models (LLMs) can occasionally provide inaccurate information.

By now, everyone should be aware that not everything AI tells you can be trusted. Threat actors are now using paid search ads on Google to share and promote conversations with ChatGPT and Grok that seem to offer tech support instructions but actually instruct macOS users to install an infostealing malware on their devices. Large language models (LLMs) can occasionally provide inaccurate information.

The campaign is an adaptation of the ClickFix assault, which frequently tricks targets into carrying out harmful commands by using CAPTCHA prompts or fictitious problem messages. However, on reputable AI platforms, the instructions are camouflaged as useful troubleshooting recommendations.

Kaspersky describes a way that attackers use ChatGPT through a campaign designed specifically for macOS Atlas installation. The first sponsored result when a user searches for a guide using the term “chatgpt atlas” is a link to chatgpt.com with the page titled as “ChatGPTTM Atlas for macOS – Download ChatGPT Atlas for Mac.” By clicking through, this will take one to the official ChatGPT website, where one will see a set of instructions which are allegedly installing Atlas.

The page, however, is a replica by duplicate of a publicly accessible chat between an anonymous user and the AI that serves as a malware installation guide. The chat also instructs the user to copy, paste, and run a program in the Terminal on your Mac, granting full access to the AMOS (Atomic macOS Stealer) infostealer.

Further investigation by Huntress where he had found similarly poisoned results in both ChatGPT and Grok when using broader troubleshooting queries and questions, such as “how to delete system data on Mac” and “clear disk space on macOS.”

Also worth reading
Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA How Dental Practices Are Embracing AI and Technology Dave Eggers Took His ChatGPT Warning Directly Inside OpenAI OpenAI Thinks the Future of ChatGPT Isn’t Typing, Its Talking AI Coding Is Creating A New Burden For Open-Source Maintainers Paystack’s AI Checkout Experiment Could Change How Nigerians Pay Online

According to the press statement by BleepingComputer, where it advised that by obtaining the root-level capabilities and targeting macOS, AMOS enables attackers to carry out commands instructions, record keystrokes, and send extra payloads. The infostealer also targets files on the disc, macOS Keychain data, browser data (including cookies, stored passwords, and autofill data), and cryptocurrency wallets.

It will be unwise to blindly follow every AI-generated command when troubleshooting technical issues. One should always carefully review any online instructions one find. Also threat actors often use sponsored search results and social media to spread ClickFix attacks. One should never execute commands if one don’t fully understand it, and even if the guidance comes from a search engine or an LLM that is trusted, it may be malicious-free especially if it advises one to run PowerShell or Terminal commands to “fix” a problem.

Of course, by asking ChatGPT (in a new discussion) whether the instructions are safe to follow, you might be able to reverse the attack as Kaspersky claims that the AI will inform you that they are not.

Also everyone can stay protected by following key security practices which includes using only official and trusted sources, avoid unofficial or not trusted downloads sources, verify developer information, be cautious with Terminal or PowerShell commands, and employ reliable security software.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • nitda-national-information-technology-development-agency
    NITDA Notifies Nigerians About ChatGPT Vulnerabilities
  • google-ads-scaled
    Attackers & Hackers Use Google Ads & Claude.AI Chats…
  • chatgpt-search-1734378724
    OpenAI Updates ChatGPT Search to Challenge Google
  • GettyImages-2203472418
    Google Rolls Out Grok Chat Search to Thousands of Users
  • handala hackers
    FBI Warns of Handala Hackers Using Telegram for Malware
  • chatgpt
    ChatGPT Gets Short-Term Boost to Custom Instructions
  • Apple_google-partner-on-covid-19-contact-tracing-technology_04102020_LP_hero.jpg.og
    Emergency Zero-Day Patch Updates From Apple & Google
  • openai-stack-overflow
    OpenAI & Stack Overflow Partner to Revamp ChatGPT…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Artificial Intelligence Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: AIChatGPTmalware
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Egypt’s PraxiLabs Wins Visa Prize As Women-Led Edtech Gets A Boost August 3, 2026
  • Busha Signal Brings Prediction Markets Into Nigeria’s Regulated Fintech Conversation August 3, 2026
  • The Metaverse Did Not Die. It Just Stopped Calling Itself The Metaverse August 2, 2026
  • Samsung Memory Warning Shows AI Chip Shortage May Last Into 2028 August 1, 2026
  • Siri AI Paywall Would Make Apple Intelligence A Services Business July 31, 2026
  • Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA July 31, 2026
  • Snapchat Stops Paying Fully AI-Generated Spotlight Videos As AI Slop Spreads July 31, 2026
  • Anthropic Says Claude Models Breached Real Systems During Cyber Tests July 31, 2026
  • DeepSeek V4 Flash API Raises The Pressure In The AI Agent Price War July 31, 2026
  • MTN Nigeria Fintech Revenue Slump Shows Airtime Lending Risk July 31, 2026
  • Google Earth AI Image Tool Shows How Fake Satellite Proof Could Spread July 31, 2026
  • Lesotho Launches National CSIRT As Cybersecurity Becomes Core Digital Infrastructure July 31, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.