Threat Advisory

ChatGPT Shared-Conversation Pages Deliver NetSupport RAT over Telegram Bot API

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A malicious campaign is abusing legitimate ChatGPT shared-conversation pages to distribute malware through a multi-stage ClickFix attack. The campaign places a fraudulent high-traffic notification within a shared ChatGPT conversation and directs users to a lookalike backup domain. The external page impersonates trusted services and presents a fake verification process designed to persuade Windows users to execute a malicious PowerShell command. This social-engineering technique abuses user trust in legitimate websites while bypassing normal browser security controls through clipboard-based command execution.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A malicious campaign is abusing legitimate ChatGPT shared-conversation pages to distribute malware through a multi-stage ClickFix attack. The campaign places a fraudulent high-traffic notification within a shared ChatGPT conversation and directs users to a lookalike backup domain. The external page impersonates trusted services and presents a fake verification process designed to persuade Windows users to execute a malicious PowerShell command. This social-engineering technique abuses user trust in legitimate websites while bypassing normal browser security controls through clipboard-based command execution.[emaillocker id="1283"]

The attack begins when the victim follows a link to the fraudulent backup site, where a fake Cloudflare and Google verification page instructs the user to paste a clipboard-provided command and execute it. The command retrieves and executes a remote PowerShell script from a malicious payload host. Subsequent stages perform anti-analysis checks, hide PowerShell windows, bypass execution-policy restrictions, and collect system information including the hostname, username, public IP address, location, ISP, operating system, architecture, timezone, and administrator status. The collected information is transmitted to a Telegram-controlled endpoint. The loader then downloads an MP4 file containing an encrypted and compressed PowerShell payload hidden within a custom UUID box. After XOR decryption and GZip decompression, the payload extracts a bundle containing multiple files, including a NetSupport remote-control client identified as NetSupport RAT. The campaign also performs cleanup operations by deleting temporary files and clearing Windows RunMRU registry history.

The campaign demonstrates how legitimate platforms and trusted brand identities can be abused to facilitate a multi-stage ClickFix-style attack. By combining social engineering, clipboard-based PowerShell execution, hidden scripting, encrypted payload delivery, host-information collection, and a legitimate remote-administration tool, the attackers can evade user suspicion and establish a pathway toward remote system access. Organizations should treat unexpected verification instructions that require users to execute commands as malicious, restrict unnecessary PowerShell execution, monitor for suspicious command-line activity and outbound connections, and investigate unauthorized deployments of remote-access software.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Resource Development T1583.001 Acquire Infrastructure Domains
Execution T1204.004 User Execution Malicious Copy and Paste
T1059.001 Command and Scripting Interpreter PowerShell
Stealth T1027.004 Obfuscated Files or Information Compile After Delivery
T1140 Deobfuscate/Decode Files or Information -
T1497.001 Virtualization/Sandbox Evasion System Checks
T1564.003 Hide Artifacts Hidden Window
T1036.008 Masquerading Masquerade File Type
T1070.004 Indicator Removal File Deletion
Defense Impairment T1112 Modify Registry -
Discovery T1082 System Information Discovery -
T1033 System Owner/User Discovery -
T1016.001 System Network Configuration Discovery Internet Connection Discovery
Command and Control T1105 Ingress Tool Transfer -
T1102.003 Web Service One-Way Communication
T1219.002 Remote Access Software Remote Desktop Software
Exfiltration T1041 Exfiltration Over C2 Channel -

 

 

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/hackers-abuse-real-chatgpt-links/

https://www.joesandbox.com/joereverser/analysis/e67c606b-37ee-4f9e-af98-428825468cb9/download?type=reports&report=html

 

[/emaillocker]
crossmenu