Cybercriminals are abusing legitimate ChatGPT shared-conversation pages to deliver NetSupport RAT through a multi-stage ClickFix campaign.
The attack combines trusted ChatGPT content, fake OpenAI and Cloudflare branding, clipboard-based PowerShell execution, and an encrypted payload hidden inside an MP4 file.
The malicious chain does not compromise the chatgpt.com domain itself. Instead, attackers use a legitimate shared ChatGPT page to display deceptive instructions.
The page tells visitors that ChatGPT is experiencing “high traffic” and directs them to an alleged backup website, openai-backup.one.
The external website impersonates OpenAI, Cloudflare, and Google. It presents a fake human-verification page designed to convince Windows users that they must complete a CAPTCHA-like process. However, the verification actually places a malicious PowerShell command into the clipboard.
The command retrieves code from brmconfig.com and executes it through PowerShell. This represents a classic ClickFix technique, where victims are manipulated into manually executing attacker-supplied commands under the belief that they are completing a security check.
ChatGPT Links Spread NetSupport RAT
The initial PowerShell stage retrieves and evaluates a remote script from brmconfig.com. The loader hides its console window, performs system checks, and launches additional PowerShell code using hidden-window and execution-policy-bypass options.
The second stage collects detailed information about the victim environment. This includes the computer name, username, Windows version, CPU architecture, administrator status, public IP address, location, ISP, and timezone.
The collected information is transmitted to an attacker-controlled Telegram chat. The campaign then downloads video.mp4 from brmconfig.com.
Despite its MP4 extension, the file contains an encrypted PowerShell payload inside a custom MP4 uuid box. The loader locates the embedded data, applies repeating-key XOR decryption, and decompresses the resulting content with GZip.
The decrypted stage contains a bundle of 20 files, including app.EXe and supporting DLL, configuration, license, and binary files.
The executable is identified as a NetSupport Client, a legitimate remote-administration component that can provide attackers with remote control of an infected system.
Joe Sandbox independently classified the same app.EXe hash as malicious in this campaign context and identified it as NetSupport RAT.
The executable is digitally signed by NetSupport Ltd., highlighting how legitimate dual-use software can be weaponized through malicious delivery chains.
The malware also performs cleanup activities. It can remove temporary scripts and clear entries under the Windows RunMRU registry location, reducing traces of commands entered through the Run dialog, joesandbox said.
The campaign demonstrates how attackers can combine trusted platforms with social engineering rather than directly exploiting the underlying service.
The ChatGPT shared page acts as the initial trust layer, while the fake verification page provides the execution mechanism and the encrypted MP4 conceals the final payload.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN