HomeSecurityPhishing attacks use ChatGPT subscriptions

Phishing attacks use ChatGPT subscriptions

A well-organized phishing attack exploiting OpenAI 's ChatGPT brand has already targeted more than 12,000 users in North America and Europe, raising concerns about the security of digital platforms.

See also: OpenAI releases AI agent Operator in multiple countries

phishing ChatGPT

The campaign exploits the display of fake ChatGPT subscription renewal notifications , aiming to collect login and payment information. It uses the platform's limited access model for the GPT-4 API and ChatGPT Plus services , misleading users with a clever approach.

Phishing emails use a multi-layered approach that combines urgency triggers, brand impersonation, and domain spoofing .

A typical phishing message carries the subject line “Action Required: Secure, Continuous Access to ChatGPT with a Monthly Subscription of $24,” and forges the sender address as noreply@chatgpt-auth[.]net. The domain was registered with PrivacyGuardian.org just 72 hours before the campaign, suggesting the organized nature of the effort.

The email content includes HTML/CSS, carefully copied from legitimate communications , using the official logo and color palette (#10A37F). However, analysis identified three significant anomalies:

See also: OpenAI ChatGPT: User growth despite competition from DeepSeek

Homograph Domain: The "Update Billing" button leads to chatgpt-payment[.]online, an address that uses Punycode to appear as "chatgpt-payment[.]online" with the Cyrillic letter "а" instead of the Latin one.

Phishing attacks use ChatGPT subscriptions

Base64 Obfuscation: The embedded URL decodes as hxxps://185[.]63[.]112[.]44/.well-known/auth, an IP that has been linked to previous Rhadamanthys malware campaigns.

Session Cookie Injection: After the form submission is complete, the website creates a persistent Secure-AuthToken cookie, which contains encrypted user metadata, using the AES algorithm.

Symantec's analysis of the attack chain reveals that the phishing kit leverages a custom ChatGPT API (version 4.8.1) to generate personalized content.

See also: ChatGPT: Outage prevents access

A phishing attack is a form of cybercrime where attackers masquerade as trusted entities to trick individuals into providing sensitive information, such as usernames, passwords, or credit card details. These attacks typically occur through fraudulent emails, websites, or messages designed to mimic legitimate sources. The goal is to manipulate victims into believing that the communication is authentic, leading them to reveal personal information or click on malicious links that compromise their security. Recognizing the telltale signs of phishing, such as generic greetings, spelling errors, or urgent demands for action, is crucial to protecting against these threats.

Source: cybersecuritynews

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS