Fake ChatGPT Invites Target Android Users With Malware
Threat actors are exploiting Google’s Firebase App Distribution service to distribute counterfeit Android applications claiming to be ChatGPT and Meta advertising tools. These applications are designed to steal Facebook credentials, facilitating…
Threat actors are exploiting Google’s Firebase App Distribution service to distribute counterfeit Android applications claiming to be ChatGPT and Meta advertising tools. These applications are designed to steal Facebook credentials, facilitating unauthorized account access.
The operation targets Android users through invitation-style emails that mimic legitimate Google communications. These emails offer early access to AI-powered advertising or ChatGPT tools, using language akin to genuine developer communications. The emails are sent from the address " [email protected] ", a legitimate Firebase App Distribution channel, enhancing their authenticity.
Recipients are directed to a Firebase App Distribution landing page by clicking "Get started" or "Install" buttons. This page, hosted on Google infrastructure, presents the app as an OpenAI, ChatGPT, or Meta Ads-related testing build, complete with version numbers and release notes. These notes often include ad credit promotions and advanced advertising features to entice marketers and Facebook page administrators.
Upon installing the Android package from Firebase, the app's functionality diverges from its advertised purpose. Instead of providing AI assistants or ad-management dashboards, the app displays a webview presenting a Facebook login screen.
These applications are designed to steal Facebook credentials, facilitating unauthorized account access.
This interface closely resembles the official Facebook mobile login page, misleading users into submitting their credentials to attacker-controlled servers. The app may also request two-factor authentication codes or business manager verifications, further compromising security. With these credentials, attackers can hijack personal profiles, business pages, and ad accounts, potentially using them for fraudulent activities.
Attackers exploit trusted AI brands and official distribution channels like Firebase App Distribution to enhance victim confidence and bypass security filters.
Android users should be cautious of unsolicited testing invitations for ChatGPT, Meta Ads, or similar tools, especially if they appear to originate from Google services. Sideloading APKs from email links should be avoided; instead, obtain apps through the official Google Play Store or verified corporate channels.
Organizations managing Facebook business assets should enforce multi-factor authentication, monitor for irregular ad spending or login locations, and educate staff that Facebook and OpenAI will not distribute tools via random Firebase or TestFlight invitations. Security teams should configure email gateways and mobile device management policies to flag unsolicited Firebase distribution links and restrict sideloading on managed Android devices.
Based on reporting by GBHackers.
