{"id":47274,"date":"2023-02-22T07:53:22","date_gmt":"2023-02-22T12:53:22","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=47274"},"modified":"2023-02-22T08:10:59","modified_gmt":"2023-02-22T13:10:59","slug":"chatgpt-stealer-win-client","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/chatgpt-stealer-win-client\/47274\/","title":{"rendered":"Malicious (and fake) ChatGPT client for Windows"},"content":{"rendered":"<p>The golden rule\u00a0\u2014 \u201cif something is popular, criminals will exploit it\u201d\u00a0\u2014 strikes once again. This time, we\u2019re talking about the trending ChatGPT chatbot, developed by OpenAI, which has been all over the news of late.<\/p>\n<h2>A word about the popularity of ChatGPT<\/h2>\n<p>When OpenAI opened access to its AI chatbot (that is, a chatbot based on neural networks trained on a vast corpus of text), the internet changed beyond recognition practically overnight.<\/p>\n<p>Users all over the planet rushed to see what the chatbot is capable of\u00a0\u2014 and were not disappointed (and often positively astonished). ChatGPT can maintain a dialog in a way that feels like there\u2019s a real person at the other end. And, more groundbreakingly, it\u2019s great at writing short texts on a given topic in a particular style, including poetry, and can adapt to a specified format and basically create texts no worse than a rookie copywriter, since it\u2019s loaded with exabytes of knowledge on every topic under the sun. You can also ask ChatGPT for advice on unfamiliar topics\u00a0\u2014 and in most cases it delivers sound tips. True, ChatGPT is equally good at <a href=\"https:\/\/www.zdnet.com\/article\/chatgpt-lies-about-scientific-results-needs-open-source-alternatives-say-researchers\/\" target=\"_blank\" rel=\"nofollow noopener\">lying and propagating errors<\/a>, but these are finer points.<\/p>\n<p>ChatGPT use is becoming mainstream, and not just for fun (to chat or, say, to ask for <em>The Hobbit<\/em> in the form of a Shakespearean sonnet \u2014 why not?), but also for business. With the help of chatbots, you can quickly fill websites with content, create product descriptions, generate quests for games, and do many other things to help people of various professions in their everyday work.<\/p>\n<p>Unsurprisingly, the ChatGPT servers were quickly overloaded, so Open AI had to increase their capacity. The company soon attracted <a href=\"https:\/\/blogs.microsoft.com\/blog\/2023\/01\/23\/microsoftandopenaiextendpartnership\/\" target=\"_blank\" rel=\"nofollow noopener\">investment from Microsoft<\/a>, and now ChatGPT has been <a href=\"https:\/\/blogs.microsoft.com\/blog\/2023\/02\/07\/reinventing-search-with-a-new-ai-powered-microsoft-bing-and-edge-your-copilot-for-the-web\/\" target=\"_blank\" rel=\"nofollow noopener\">integrated into Bing<\/a>, albeit with <a href=\"https:\/\/www.engadget.com\/microsoft-limits-bing-conversations-to-prevent-disturbing-chatbot-responses-154142211.html\" target=\"_blank\" rel=\"nofollow noopener\">restrictions<\/a>. In response, Google rushed to roll out its own neural network, <a href=\"https:\/\/blog.google\/technology\/ai\/bard-google-ai-search-updates\/\" target=\"_blank\" rel=\"nofollow noopener\">Bard<\/a>, which has similar capabilities but was not considered by the company to be fully ready for market launch.<\/p>\n<p>We\u2019ve already written about <a href=\"https:\/\/www.kaspersky.com\/blog\/chatgpt-cybersecurity\/46959\/\" target=\"_blank\" rel=\"noopener nofollow\">how ChatGPT will change the world of cybersecurity<\/a>, but for now at least the use of chatbots in phishing attacks or malware development remains at the theoretical stage. In practice, however, ChatGPT is already being used as bait to spread malware.<\/p>\n<h2>What attracts scammers to ChatGPT<\/h2>\n<p>Why are scammers suddenly using ChatGPT as bait? Simply because the service is hugely popular.<\/p>\n<p>Although ChatGPT is technically free, it\u2019s not always easy to access it. First, to register an account on the OpenAI website, you need to enter your e-mail address and phone number. But not all country codes are accepted: ChatGPT registration is currently unavailable in Russia, China, Egypt, Iran and some other countries. So not everyone can get an account easily.<\/p>\n<p>Second, even if you managed to create an account on the OpenAI website, it\u2019s not a given that you\u2019ll be able to actually use ChatGPT: the service is almost always overloaded with users wanting to try out the AI, ask it to write a marketing blurb, or give it some other tasks. The inflow of users was so great that OpenAI introduced a <a href=\"https:\/\/openai.com\/blog\/chatgpt-plus\/\" target=\"_blank\" rel=\"nofollow noopener\">subscription plan<\/a> with priority access and faster text generation for US$20 a month.<\/p>\n<p>High demand and low availability. That\u2019s enough for scammers.<\/p>\n<h2>The desktop client that never was<\/h2>\n<p>Kaspersky experts have uncovered a malicious campaign exploiting the growing popularity of ChatGPT. Fraudsters create groups on social networks that convincingly mimic, if not official OpenAI accounts, then at least communities of enthusiasts. These groups publish equally persuasive posts: say, that ChatGPT hit one million users faster than any other service. At the bottom of the post is a link for supposedly downloading a ChatGPT desktop client.<\/p>\n<div id=\"attachment_47276\" style=\"width: 358px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22054817\/chat-gpt-stealer-win-client-01.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-47276\" class=\"size-full wp-image-47276\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22054817\/chat-gpt-stealer-win-client-01.png\" alt=\"Impressive stats and a handy link\u00a0\u2014 just how we like it\" width=\"348\" height=\"374\"><\/a><p id=\"caption-attachment-47276\" class=\"wp-caption-text\">Impressive stats and a \u201chandy\u201d link\u00a0\u2014 just how we like it<\/p><\/div>\n<p>Also posted in these groups are fake credentials for the precreated accounts that are said to provide access to ChatGPT. To motivate potential users even further, the attackers say that each account already has US$50 on its balance, which can be spent on using the chatbot. It all feels like a genuine opportunity to use ChatGPT without the trouble of creating an account, and even to get premium features for free: just download the desktop client and sit back for the ride.<\/p>\n<div id=\"attachment_47277\" style=\"width: 698px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22054835\/chat-gpt-stealer-win-client-02.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-47277\" class=\"size-full wp-image-47277\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22054835\/chat-gpt-stealer-win-client-02.png\" alt=\"Roll up, roll up, get your desktop chatbot while you can!\" width=\"688\" height=\"438\"><\/a><p id=\"caption-attachment-47277\" class=\"wp-caption-text\">Roll up, roll up, get your desktop chatbot while you can!<\/p><\/div>\n<p>You can probably guess what happens next, but we\u2019ll tell you anyway. Clicking the link with a very plausible URL opens a well-made site inviting you to download ChatGPT for Windows. It\u2019s not the official site, of course, but very like the original. If you click on the download button, an archive with an executable file is indeed downloaded.<\/p>\n<div id=\"attachment_47278\" style=\"width: 1610px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22054945\/chat-gpt-stealer-win-client-03.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-47278\" class=\"size-full wp-image-47278\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22054945\/chat-gpt-stealer-win-client-03.jpg\" width=\"1600\" height=\"986\"><\/a><p id=\"caption-attachment-47278\" class=\"wp-caption-text\">The scam site is a carbon copy of the original, only instead of the \u201cTry ChatGPT\u201d button there is a \u201cDownload for Windows\u201d button<\/p><\/div>\n<p>If this archive is unpacked and the executable file run, then, depending on the version of Windows, the user sees either a message saying installation failed for some reason, or no message at all\u00a0\u2014 at which point the process seems to end. \u201cShame I didn\u2019t get to use a <em>precreated account with premium features<\/em>\u201c, the user will think, and forget about the incident \u2014 probably resorting to creating a regular account on the real ChatGPT site.<\/p>\n<div id=\"attachment_47279\" style=\"width: 357px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22055113\/chat-gpt-stealer-win-client-04.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-47279\" class=\"size-full wp-image-47279\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22055113\/chat-gpt-stealer-win-client-04.png\" alt=\"If you see this message (or no message at all), the Trojan installed successfully\" width=\"347\" height=\"149\"><\/a><p id=\"caption-attachment-47279\" class=\"wp-caption-text\">If you see this message (or no message at all), the Trojan installed successfully<\/p><\/div>\n<p>In fact, installation did not fail: a <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/trojan-psw-psw-password-stealing-ware\/\" target=\"_blank\" rel=\"noopener\">stealer Trojan<\/a> is installed on the user\u2019s computer, from where it pinches account credentials stored in Chrome, Edge, Firefox, Brave, C\u00f4cC\u00f4c (popular in Vietnam), and other browsers. We\u2019ve dubbed it <strong>Trojan-PSW.Win64.Fobo<\/strong>.<\/p>\n<p>The Trojan\u2019s creators are interested in Facebook, TikTok, and Google cookies and accounts \u2014 in particular business accounts. The virus steals usernames and passwords, then, on finding a business account in one of these services, it tries to get additional information, such as how much money was spent on advertising from the account and what its current balance is.<\/p>\n<p>According to our data, the attackers target the international market \u2014 the \u201cChatGPT desktop client\u201d has already been spotted in Asia, Africa, Europe and America.<\/p>\n<h2>How to use ChatGPT safely<\/h2>\n<p>For starters, note that there\u2019s no official desktop, mobile, or other client for ChatGPT\u00a0\u2014 only the web version. Amusingly, the chatbot itself makes this very point when asked to write a blog post about this scam campaign.<\/p>\n<div id=\"attachment_47280\" style=\"width: 1206px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22055202\/chat-gpt-stealer-win-client-05.png\"><img decoding=\"async\" aria-describedby=\"caption-attachment-47280\" class=\"size-full wp-image-47280\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2023\/02\/22055202\/chat-gpt-stealer-win-client-05.png\" alt=\"What ChatGPT itself thinks of this scam campaign\" width=\"1196\" height=\"1562\"><\/a><p id=\"caption-attachment-47280\" class=\"wp-caption-text\">What ChatGPT itself thinks of this scam campaign<\/p><\/div>\n<p>There\u2019s also no need to use \u201cprecreated\u201d accounts, of course. Currently, OpenAI\u2019s only paid feature is a monthly subscription with priority access, otherwise access to ChatGPT is completely free. So you can register a real ChatGPT account for free, no strings attached. Even if your phone number is no good due to restrictions on some countries, you can ask a friend abroad to buy you a disposable SIM card or use a temporary phone number \u2014 you only need it once, to activate the account. There are plenty of services that offer temporary phone numbers for receiving verification codes by text: just google \u201cone-time phone number\u201d.<\/p>\n<p>The main thing is to make sure you land on the official site (<a href=\"https:\/\/chat.openai.com\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/chat.openai.com<\/a>). To do that, don\u2019t follow a link, rather enter the URL in the address bar yourself.<\/p>\n<p>And have a good <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">security solution<\/a> installed on your computer \u2014 ChatGPT is only gaining popularity, and attackers are bound to come up with more campaigns centered on this revolutionary new chatbot. Sure, vigilance is vital, but sometimes even the most attentive and super-prepared fall for phishing or well-faked sites, so it\u2019s better to play it safe. <a href=\"https:\/\/www.kaspersky.com\/?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener nofollow\">All Kaspersky security solutions<\/a> detect <strong>Trojan-PSW.Win64.Fobo<\/strong> and keep it off your computer.<\/p>\n<p>As for ChatGPT desktop clients, they\u2019re bound to appear sooner or later \u2014 if not official, then third-party ones. But always <a href=\"https:\/\/www.kaspersky.com\/blog\/why-messenger-mods-are-dangerous\/45788\/\" target=\"_blank\" rel=\"noopener nofollow\">think thrice<\/a> before using any kind of third-party client, and here an antivirus is a no-brainer.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are distributing a Trojan stealer under the guise of a ChatGPT desktop client for Windows. We delve into the details and ways to protect yourself.<\/p>\n","protected":false},"author":2730,"featured_media":47288,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,2683],"tags":[1140,960,4414,80,726,422,723],"class_list":{"0":"post-47274","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-ai","10":"tag-artificial-intelligence","11":"tag-chatgpt","12":"tag-fraud","13":"tag-scam","14":"tag-threats","15":"tag-trojans"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/chatgpt-stealer-win-client\/47274\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/chatgpt-stealer-win-client\/25246\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/chatgpt-stealer-win-client\/20727\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/chatgpt-stealer-win-client\/27902\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/chatgpt-stealer-win-client\/25570\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/chatgpt-stealer-win-client\/25991\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/chatgpt-stealer-win-client\/28446\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/chatgpt-stealer-win-client\/34738\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/chatgpt-stealer-win-client\/20797\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/chatgpt-stealer-win-client\/29814\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/chatgpt-stealer-win-client\/33298\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/chatgpt-stealer-win-client\/25901\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/chatgpt-stealer-win-client\/31599\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/chatgpt-stealer-win-client\/31314\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/threats\/","name":"threats"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/47274","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2730"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=47274"}],"version-history":[{"count":5,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/47274\/revisions"}],"predecessor-version":[{"id":47291,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/47274\/revisions\/47291"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/47288"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=47274"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=47274"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=47274"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}