By: Josh Varden, Cofense Phishing Defense Center
As generative AI tools like OpenAI’s ChatGPT become increasingly common, their large user bases create new opportunities for threat actors. ChatGPT offers subscription-based access to additional features, providing attackers with a familiar payment process to impersonate. By sending fake notifications claiming that a user’s payment method needs to be updated, threat actors can turn a routine billing request into a phishing lure designed to steal credentials and payment information.
The Cofense Phishing Defense Center (PDC) recently identified a fraudulent subscription invoice email that aimed to steal account credentials for users’ OpenAI accounts, preying on users who utilize ChatGPT either through a work account or a personal account. The PDC has identified many other examples of similar credential stealing phish, most commonly spoofing Microsoft, Google, and Adobe. With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT. Utilizing similar tactics to other phishing examples, the threat actors frequently exploit urgency and perceived trustworthiness to manipulate users into taking actions that compromise their security.
.png?language=en)
Figure 1: Email Body
The main body of the email above looks to be an average bill or invoice message. However, threat actors often rely on building fake trust with victims using familiar images, bold text, and urgency to get a message across. In this example, the image at the top of the email shows the real ChatGPT logo. This is already building trust and legitimacy with the receiver due to using the correct brand asset. The use of bold text also conveys a sense of urgency. Using phrases in bold like “Subscription Payment Required” at the top of the message and “48 hours” to indicate a timeframe in which an action needs to be completed encourages the recipient to take immediate action without carefully evaluating the legitimacy of the email. A large button in the center of the email is present with the words “Update Payment Information,” prompting the user to click on the button to proceed to a new webpage. The email closes out by thanking the customer and signing it from “The OpenAI Team.” These could all be taken as signs of legitimacy. However, taking a closer look at the top of the email, specifically the from address, one might notice that it is from “support@9527db6e1a[.]nxcli[.]io.” This is not a legitimate address from OpenAI or ChatGPT. Utilizing the hover test over the button would also reveal its illegitimacy. Specifically, it uses a Google API wrapper URL, which then redirects to the real malicious payload (see table below). After clicking the button, it will take you to a webpage where a user could make a sign-in attempt (Figure 2).
.png?language=en)
Figure 2: Phishing Page
Upon clicking the button shown in Figure 1, the page redirects to the image shown above. It brings you to a page that looks strikingly similar to the ChatGPT login. Once again, it creates a sense of trustworthiness by welcoming the user back and utilizing legitimate logos, text, and icons. However, looking at the search bar reveals that this is not real. The correct ChatGPT domain would be hxxps[://]auth[.]openai[.]com/log-in-or-create-account, which the displayed domain does not match. Entering credentials further redirects the user to an error page after stealing the entered information and sending it to the attacker.
While AI chatbots are extremely helpful tools in performing repetitive tasks, users need to be aware that, like with all account creation, the threat of credential theft is still persistent. Whether it is a traditional phishing attack similar to the one described in this article or the use of smishing/vishing, attackers are constantly finding unique pathways through security systems and secure email gateways (SEGs). Cofense, Cofense Managed Phishing Defense, and the PDC are positioned to find, detect, and alert businesses to real phishing threats with speed and precision. Contact Cofense to learn more.
Email(s) IOCs:
Stage 1 - Observed Email Infection URL: | Infection URL IP(s): |
hXXps://notifications[.]googleapis[.]com/email/redirect?t=AFG8qyW_Su5LnlMKcIA7MTSSwtdIBp6-pVpWF_Tm7YFcNgju_01zhPKtjCpIcIfTVDTsqk_NT5E4LWD15nZyb_erqoslbxoHKRH8O_TRSdvyON9ZbKAejE3mykvuQ2_t43Pveg7wh8bYrPQvCoCTK_XbSbXSCAsu3vTNbz0XJSMLjnnC.... |
Stage 2 – Observed Payload URL(s): | Payload IP(s): |
hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/login[.]php |
All third-party trademarks referenced by Cofense whether in logo form, name form or product form, or otherwise, remain the property of their respective holders, and use of these trademarks in no way indicates any relationship between Cofense and the holders of the trademarks. Any observations contained in this blog regarding circumvention of end point protections are based on observations at a point in time based on a specific set of system configurations. Subsequent updates or different configurations may be effective at stopping these or similar threats. Past performance is not indicative of future results.
The Cofense® and PhishMe® names and logos, as well as any other Cofense product or service names or logos displayed on this blog are registered trademarks or trademarks of Cofense Inc