In recent weeks, a sophisticated phishing campaign has emerged targeting both corporate and consumer users , spoofing the login portals of OpenAI and Sora . The scammers send well-crafted emails that resemble official service notifications , warning of a supposed account suspension or unusual activity . The attackers’ goal is to trick users into submitting their credentials.

Phishing tricks
The messages include links to fake pages that replicate SSL certificates and the visuals of the genuine OpenAI and Sora, making the difference indistinguishable even to experienced users. Early reports emerged when organizations detected unauthorized accessimmediately after employees clicked on such decoys. The quality of the messages—with targeted content and social engineering techniques—indicates that the attackers have prepared the campaign in a professional manner.
See also: Pixnapping attack: Malicious Android apps steal 2FA codes
Multi-stage loader and hiding strategy
Security researchers at Unit 42 have identified a multi-stage loader written in obfuscated JavaScript that dynamically injects malicious payloads browsers victims’ collects usernames and passwords and sends them to a command and control (C2) server before redirecting the user to the legitimate service. This tactic acts as a “cover”: it reduces suspicion, as the end user quickly sees the genuine page, while the criminals extract large amounts of credentials from both corporate and personal profiles.

OpenAI and Sora Abuse: Risks and Operational Impact
The impact is critical. Stolen credentials can allow access to sensitive data, be used to manipulate AI models , or launch additional attacks. Particularly vulnerable are systems that rely on Single Sign-On (SSO), where obtaining a token can provide lateral movement within corporate networks and facilitate privilege escalation. The attackers’ ability to remain undetected allows for long-term credential collection and greater damage.
See also: RMPocalypse attack allows AMD SEV-SNP compromise
Recommendations for security teams
Guidance for security teams includes reviewing recent login activity, implementing multi-factor authentication (MFA) where possible, and continuously monitoring outbound traffic for connections to known malicious domains. Additionally, training staff to recognize suspicious emails and social engineering techniques remains critical. Systematic checks for unusual sessions, mismatches in the geographic origin of connections , and rapid credential suspension processes can limit the spread.
Technical details of infection and persistence
The campaign’s core is a JavaScript loader, which is activated immediately after login credentials are submitted to the phishing page. The code appears to be largely obfuscated, with custom string-encoding routines; once decoded, it communicates with C2 endpoints and retrieves complex payloads to execute in the victim’s browser environment. This dynamic loading makes it difficult to detect with traditional signatures, since the actual malicious code is never displayed on the home page. In addition, local storage and session resume scripts are leveraged so that the loader is reactivated even if the user clears cookies or closes the tab.
See also: Russian TwoNet Group Attacks OT/ICS Devices

Practical response steps
Teams must immediately isolate suspicious sessions, revoke stolen tokens, push security updates , and perform forensic analysis to identify the source and extent of the breach. Partnering with identity providers, educating consumers, and sharing breach indicators with Threat Intelligence communities accelerate detection and reduce the success of future campaigns. Responding promptly reduces risk, saves resources, and protects the organization’s reputation.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
