Sophos, a global leader in innovating and delivering cybersecurity as a service, today announced that it had uncovered multiple apps masquerading as legitimate, ChatGPT-based chatbots to overcharge users and bring in thousands of dollars a month. As detailed in Sophos X-Ops’ latest report, “’FleeceGPT’ Mobile Apps Target AI-Curious to Rake in Cash,” these apps have popped up in both the Google Play and Apple App Store, and, because the free versions have near-zero functionality and constant ads, they coerce unsuspecting users into signing up for a subscription that can cost hundreds of dollars a year.
“Scammers have and always will use the latest trends or technology to line their pockets. ChatGPT is no exception. With interest in AI and chatbots arguably at an all-time high, users are turning to the Apple App and Google Play Stores to download anything that resembles ChatGPT. These types of scam apps—what Sophos has dubbed ‘fleeceware’—often bombard users with ads until they sign up for a subscription. They’re banking on the fact that users won’t pay attention to the cost or simply forget that they have this subscription. They’re specifically designed so that they may not get much use after the free trial ends, so users delete the app without realizing they’re still on the hook for a monthly or weekly payment,” said Sean Gallagher, principal threat researcher, Sophos.
In total, Sophos X-Ops investigated five of these ChatGPT fleeceware apps, all of which claimed to be based on ChatGPT’s algorithm. In some cases, as with the app “Chat GBT,” the developers played off the ChatGPT name to improve their app’s ranking in the Google Play or App Store. While OpenAI offers the basic functionality of ChatGPT to users for free online, these apps were charging anything from $10 a month to $70.00 a year. The iOS version of “Chat GBT,” called Ask AI Assistant, charges $6 a week—or $312 a year—after the three-day free trial; it netted the developers $10,000 in March alone. Another fleeceware-like app, called Genie, which encourages users to sign up for a $7 weekly or $70 annual subscription, brought in $1 million over the past month.
The key characteristics of so-called fleeceware apps, first discovered by Sophos in 2019, are overcharging users for functionality that is already free elsewhere, as well as using social engineering and coercive tactics to convince users to sign up for a recurring subscription payment. Usually, the apps offer a free trial but with so many ads and restrictions, they’re barely useable until a subscription is paid. These apps are often poorly written and implemented, meaning app function is often less than ideal even after users switch to the paid version. They also inflate their ratings in the app stores through fake reviews and persistent requests of users to rate the app before it’s even been used or the free trial ends.
“Fleeceware apps are specifically designed to stay on the edge of what’s allowed by Google and Apple in terms of service, and they don’t flout the security or privacy rules, so they are hardly ever rejected by these stores during review. While Google and Apple have implemented new guidelines to curb fleeceware since we reported on such apps in 2019, developers are finding ways around these policies, such as severely limiting app usage and functionality unless users pay up. While some of the ChatGPT fleeceware apps included in this report have already been taken down, more continue to pop up—and it’s likely more will appear. The best protection is education. Users need to be aware that these apps exist and always be sure to read the fine print whenever hitting ‘subscribe.’ Users can also report apps to Apple and Google if they think the developers are using unethical means to profit,” said Gallagher.
All apps included in the report have been reported to Apple and Google. For users who have already downloaded these apps, they should follow the App or Google Play store’s guidelines on how to “unsubscribe.” Simply deleting the fleeceware app will not void the subscription.
20 comments
brand atorvastatin 80mg atorvastatin 20mg brand atorvastatin 10mg generic
ciplox 500mg brand – purchase amoxicillin without prescription
buy generic erythromycin for sale
ivermectin 3 mg tablet – cefixime 200mg sale sumycin pills
lasix pill – order tacrolimus pills capoten 120mg drug
buy glycomet 1000mg generic – lamivudine pill buy lincocin cheap
order retrovir 300 mg online pill – zyloprim 300mg tablet
buy quetiapine 100mg generic – buy bupropion for sale eskalith where to buy
buy clomipramine tablets – order paxil 20mg generic buy doxepin 75mg generic
atarax online order – pamelor 25 mg cost endep 25mg drug
amoxicillin generic – buy cefadroxil 250mg sale buy baycip pill
cleocin 150mg canada – chloramphenicol generic chloromycetin cost
generic ivermectin for humans – buy cefaclor 500mg online buy cefaclor 500mg pill
buy antihistamine pills – purchase fluticasone without prescription theophylline 400 mg pill
buy desloratadine generic – where to buy flixotide without a prescription albuterol order
methylprednisolone for sale – brand cetirizine 10mg buy astelin 10ml generic
order micronase 2.5mg generic – brand forxiga 10 mg cost forxiga 10 mg
buy prandin 2mg online – order repaglinide 1mg online empagliflozin pills
metformin us – buy metformin 1000mg without prescription purchase acarbose online cheap
oral semaglutide – purchase desmopressin without prescription desmopressin price
order nizoral 200mg pill – butenafine buy sporanox pills for sale