Hackers Abuse ChatGPT Shared Links and Fake Cloudflare CAPTCHA to Deploy NetSupport RAT
Brief
Cybercriminals are abusing legitimate ChatGPT shared-conversation pages to deliver NetSupport RAT through a multi-stage ClickFix campaign.
The attack combines trusted ChatGPT content, fake OpenAI and Cloudflare branding, clipboard-based PowerShell execution, and an encrypted payload hidden inside an MP4 file.
The malicious chain does not compromise the chatgpt. com domain itself. Instead, attackers use a legitimate shared ChatGPT page to display deceptive instructions.
The page tells visitors that ChatGPT is experiencing “high traffic” and directs them to an alleged backup website, openai-backup.one .
The external website impersonates OpenAI, Cloudflare, and Google. It presents a fake human-verification page designed to convince Windows users that they must complete a CAPTCHA-like process. However, the verification actually places a malicious PowerShell command into the clipboard.
