• Home
  • Blog
  • Business
  • Entertainment
  • Real Estate
  • Sports
No Result
View All Result
Pakistan Tribune
  • Home
  • Blog
  • Business
  • Entertainment
  • Real Estate
  • Sports
No Result
View All Result
Pakistan Tribune
No Result
View All Result

Hackers Are Disguising Malware as Fake ChatGPT Apps — Microsoft Issues Warning

Imran Malik by Imran Malik
August 20, 2025
in Tech
0 0
0
Hackers Are Disguising Malware as Fake ChatGPT Apps — Microsoft Issues Warning

A new wave of cyberattacks is targeting unsuspecting users with what looks like a legitimate “ChatGPT desktop app,” but in reality, it’s a sophisticated piece of malware. Microsoft has identified the threat as PipeMagic, a modular backdoor that takes advantage of a zero-day vulnerability in Windows (CVE-2025-29824).

Once installed, PipeMagic can do much more than steal files — it enables surveillance, credential theft, and in some cases, ransomware deployment.

How the Malware Masquerade Works

The malicious campaign begins with attackers modifying an open-source ChatGPT project on GitHub, slipping in hidden code that activates immediately after launch. Victims think they’re opening an AI chatbot, but the program silently loads PipeMagic instead.

The malware’s design is modular, meaning it can load different components depending on the attacker’s goals. It uses encrypted pipes and in-memory execution to avoid detection, a technique that makes it far harder for traditional antivirus systems to catch.

In recent attacks targeting Saudi Arabia and Brazil, hackers used a Microsoft Help Index file (.mshi) as the loader. That file decrypts and runs embedded shellcode written in C#, effectively opening the door for the malware to take control.

Who’s Behind It? A Familiar Name in Ransomware

Microsoft attributes the campaign to Storm-2460, a cybercrime group previously linked to RansomEXX ransomware attacks. This is not a newcomer; the group has been active across finance, real estate, and IT industries, with victims reported in the U.S., Europe, South America, and the Middle East.

Their pivot to using AI branding as bait is significant — it plays on the public’s growing trust in generative AI tools, making the disguise more convincing.

Techniques Borrowed from Legitimate Tools

Security researchers from Kaspersky and BI.ZONE have traced PipeMagic’s inner workings, finding that it abuses the CLFS logging driver in Windows to gain persistence. Some modules rely on DLL hijacking or Microsoft Help files to deploy stealth payloads.

Even more troubling, attackers repurpose built-in Windows tools for malicious purposes. For example, they’ve been caught using ProcDump — disguised as dllhost.exe — to pull sensitive login credentials from memory. This blending of legitimate and malicious activity makes detection even harder.

How Users Can Stay Protected

Microsoft has flagged the malware under the name Backdoor:Win32/PipeMagic!MSR, but defense still relies heavily on user caution and timely patching. Here are the key steps:

  • Only download ChatGPT tools from trusted sources — avoid third-party “desktop apps” floating around GitHub or forums.
  • Update Windows immediately — patching closes the zero-day hole PipeMagic exploits.
  • Run a full scan if you’ve already installed a questionable ChatGPT app.

Why This Matters

The rise of PipeMagic underscores how cybercriminals exploit popular technology brands to gain trust. AI tools like ChatGPT have become household names, which makes them perfect camouflage for malware distribution.

The bottom line: convenience can be costly. If you want ChatGPT on your desktop, stick to the official sources — anything else could be opening the door to ransomware.

Previous Post

Punjab Boards Release 9th Class Results for 2025

Imran Malik

Imran Malik

Imran Malik is a political and social affairs journalist delivering SEO-focused news and analysis. He covers key developments, movements, and policies shaping Pakistan’s national discourse.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You might also like

Hackers Are Disguising Malware as Fake ChatGPT Apps — Microsoft Issues Warning

Hackers Are Disguising Malware as Fake ChatGPT Apps — Microsoft Issues Warning

August 20, 2025
Punjab Boards Release 9th Class Results for 2025

Punjab Boards Release 9th Class Results for 2025

August 20, 2025
FBR Unveils Streamlined Online Tax Return System for 2025

FBR Unveils Streamlined Online Tax Return System for 2025

August 20, 2025
Tradition Meets Transition Toyota Hilux Revo Rocco vs Riddara RD6

Tradition Meets Transition: Toyota Hilux Revo Rocco vs Riddara RD6

August 20, 2025
Pakistan and Iran Push for $3 Billion Agriculture Trade by 2026

Pakistan and Iran Push for $3 Billion Agriculture Trade by 2026

August 19, 2025
Rain-Triggered Landslide Disrupts Murree Expressway

Rain-Triggered Landslide Disrupts Murree Expressway

August 19, 2025
Pakistan Tribune

Stay connected with Pakistan Tribune for timely news updates. Your reliable source for comprehensive and unbiased coverage across various domains.

Stay Connected

  • Home
  • Blog
  • Business
  • Entertainment
  • Real Estate
  • Sports

© 2024 Pakistan Tribune

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Blog
  • Business
  • Entertainment
  • Real Estate
  • Sports

© 2024 Pakistan Tribune