EXECUTIVE SUMMARY:
A malicious campaign is abusing legitimate ChatGPT shared-conversation pages to distribute malware through a multi-stage ClickFix attack. The campaign places a fraudulent high-traffic notification within a shared ChatGPT conversation and directs users to a lookalike backup domain. The external page impersonates trusted services and presents a fake verification process designed to persuade Windows users to execute a malicious PowerShell command. This social-engineering technique abuses user trust in legitimate websites while bypassing normal browser security controls through clipboard-based command execution.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A malicious campaign is abusing legitimate ChatGPT shared-conversation pages to distribute malware through a multi-stage ClickFix attack. The campaign places a fraudulent high-traffic notification within a shared ChatGPT conversation and directs users to a lookalike backup domain. The external page impersonates trusted services and presents a fake verification process designed to persuade Windows users to execute a malicious PowerShell command. This social-engineering technique abuses user trust in legitimate websites while bypassing normal browser security controls through clipboard-based command execution.[emaillocker id="1283"]
The attack begins when the victim follows a link to the fraudulent backup site, where a fake Cloudflare and Google verification page instructs the user to paste a clipboard-provided command and execute it. The command retrieves and executes a remote PowerShell script from a malicious payload host. Subsequent stages perform anti-analysis checks, hide PowerShell windows, bypass execution-policy restrictions, and collect system information including the hostname, username, public IP address, location, ISP, operating system, architecture, timezone, and administrator status. The collected information is transmitted to a Telegram-controlled endpoint. The loader then downloads an MP4 file containing an encrypted and compressed PowerShell payload hidden within a custom UUID box. After XOR decryption and GZip decompression, the payload extracts a bundle containing multiple files, including a NetSupport remote-control client identified as NetSupport RAT. The campaign also performs cleanup operations by deleting temporary files and clearing Windows RunMRU registry history.
The campaign demonstrates how legitimate platforms and trusted brand identities can be abused to facilitate a multi-stage ClickFix-style attack. By combining social engineering, clipboard-based PowerShell execution, hidden scripting, encrypted payload delivery, host-information collection, and a legitimate remote-administration tool, the attackers can evade user suspicion and establish a pathway toward remote system access. Organizations should treat unexpected verification instructions that require users to execute commands as malicious, restrict unnecessary PowerShell execution, monitor for suspicious command-line activity and outbound connections, and investigate unauthorized deployments of remote-access software.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Resource Development | T1583.001 | Acquire Infrastructure | Domains |
| Execution | T1204.004 | User Execution | Malicious Copy and Paste |
| T1059.001 | Command and Scripting Interpreter | PowerShell | |
| Stealth | T1027.004 | Obfuscated Files or Information | Compile After Delivery |
| T1140 | Deobfuscate/Decode Files or Information | - | |
| T1497.001 | Virtualization/Sandbox Evasion | System Checks | |
| T1564.003 | Hide Artifacts | Hidden Window | |
| T1036.008 | Masquerading | Masquerade File Type | |
| T1070.004 | Indicator Removal | File Deletion | |
| Defense Impairment | T1112 | Modify Registry | - |
| Discovery | T1082 | System Information Discovery | - |
| T1033 | System Owner/User Discovery | - | |
| T1016.001 | System Network Configuration Discovery | Internet Connection Discovery | |
| Command and Control | T1105 | Ingress Tool Transfer | - |
| T1102.003 | Web Service | One-Way Communication | |
| T1219.002 | Remote Access Software | Remote Desktop Software | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/hackers-abuse-real-chatgpt-links/
https://www.joesandbox.com/joereverser/analysis/e67c606b-37ee-4f9e-af98-428825468cb9/download?type=reports&report=html
[/emaillocker]