Hackers Abuse Legitimate ChatGPT Shared Links to Deploy NetSupport RAT
ID: 80674e89-778d-59f1-aee2-06aacb22ee97
STIX ID: report--80674e89-778d-59f1-aee2-06aacb22ee97
Feed Name: GBHackers
Threat actors are abusing legitimate ChatGPT shared-conversation URLs to host social-engineering lures that push victims to a fake "backup" domain which uses a ClickFix technique to get users to run a PowerShell command from the Run dialog; that command fetches a staged loader from brmconfig[.]com which unpacks an MP4-embedded payload and ultimately installs NetSupport RAT. The report details multi-stage PowerShell loaders with anti-analysis and persistence checks, telemetry exfiltration to a Telegram bot, IOCs (domains, SHA-256 of app.EXe, UUID), recommended defensive actions (block domains, hunt for IEX(irm patterns, inspect RunMRU and PowerShell logging), and user training guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
