$ techbeacon▋
Phishing

Hackers Leverage ChatGPT Share Links to Distribute NetSupport Remote‑Access Trojan

Hackers Leverage ChatGPT Share Links to Distribute NetSupport Remote‑Access Trojan

Security researchers have identified a new abuse vector that repurposes legitimate ChatGPT shared‑conversation URLs as a delivery mechanism for a remote‑access tool (RAT) known as NetSupport. The scheme begins with a seemingly innocuous link to a ChatGPT dialogue, but it quickly redirects victims into a multi‑stage infection chain reminiscent of the ClickFix malware installers.

ChatGPT’s “share conversation” feature generates a short, publicly accessible URL that anyone can open to view the AI’s response. Threat actors are embedding malicious prompts or enticing calls‑to‑action within these pages, prompting users to click on additional links that appear to be part of the AI interaction. Because the initial URL points to an official OpenAI domain, the lure can bypass many basic security filters that flag suspicious domains.

Once a user follows the embedded link, they encounter a download disguised as a legitimate utility—often presented as a system‑maintenance or troubleshooting tool. This mirrors the ClickFix approach, where the installer masquerades as a helpful program while silently bundling malicious payloads. Execution of the payload installs the NetSupport RAT, granting the attacker persistent remote control over the compromised system.

NetSupport RAT is a well‑known remote‑access framework that enables operators to view screens, record keystrokes, transfer files, and execute commands. Its capabilities make it attractive for espionage, data theft, and further lateral movement within networks. By coupling the RAT with a trusted‑looking delivery chain, threat actors increase the likelihood of successful infection and prolonged access.

The tactic reflects a broader trend of cybercriminals hijacking legitimate platforms—such as cloud storage services, social media, and now AI chat tools—to evade detection. Past incidents have seen attackers exploit file‑sharing sites and document collaboration services for similar purposes. The use of ChatGPT links is notable because the service is widely trusted and its URLs are often whitelisted in corporate environments.

Experts advise users to treat any unsolicited link, even those pointing to reputable domains, with caution. Verifying the source, avoiding unexpected downloads, and maintaining up‑to‑date endpoint protection can mitigate the risk. OpenAI has not publicly commented on the specific abuse, but the incident underscores the need for continuous monitoring of how emerging technologies are leveraged in cyber‑threat campaigns.

Source: GBHackers
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related