Windows users are facing a new cyber threat as hackers leverage ChatGPT links to distribute malware. This campaign manipulates shared ChatGPT URLs, tricking users into executing malicious commands on their systems.
How the Attack Unfolds
Instead of compromising the ChatGPT platform, attackers embed misleading messages within shared ChatGPT conversations. Victims are urged to visit a backup site, claiming high traffic on the original page. This site presents a fake human-verification screen, instructing users to open Windows Run, paste a command, and press Enter.
This deceptive action initiates a PowerShell-based download outside the browser, identified by JOERverser analysts as a ClickFix operation. Crucially, the legitimate ChatGPT domain remains uncompromised, highlighting the danger of malicious user-controlled content.
Implications and Analysis
According to Joe Reverser’s report for Cyber Security News, this campaign can reveal sensitive information about a victim’s computer. The malware retrieves a concealed software bundle containing a NetSupport remote-control client, posing significant risks of unauthorized access and monitoring.
The attack begins with genuine ChatGPT sharing URLs, misleading users with an availability warning and a link to an unrelated site. This tactic exploits the credibility of well-known services without breaching their infrastructure. By pairing AI branding with ClickFix prompts, attackers guide users toward manual command execution.
Execution and Concealment Techniques
The landing page uses OpenAI-themed wording and Cloudflare-style verification to seem legitimate. A button copies a PowerShell command to the clipboard, leading users through familiar sequences to execute the command via Windows features.
This approach minimizes traditional phishing warnings by avoiding direct file downloads. Instead, the victim unknowingly initiates the attack through built-in Windows functionality, bypassing usual security alerts.
The hidden command fetches a remote script, collecting device and network data and sending it to a Telegram chat. The script conceals its activity by hiding the console window and using execution-policy bypass settings, adding further PowerShell stages.
Mitigation and Precautions
To avoid falling victim to such attacks, users should be cautious of websites requesting them to open system utilities like Run or PowerShell. It’s advisable to close such pages and inspect clipboard content before executing commands. Organizations should also block related infrastructure and investigate relevant hashes to prevent malicious activities.
Indicators of compromise include specific URLs, domains, and file names linked to this malware campaign. Security teams are advised to monitor these indicators actively and report suspicious activities promptly.
In conclusion, vigilance and proactive security measures are essential to combat the evolving strategies of cybercriminals leveraging trusted platforms like ChatGPT to propagate malware.
