HomeSecurityHackers imitate OpenAI and Sora to steal credentials

Hackers impersonate OpenAI and Sora to steal credentials

In recent weeks, a sophisticated phishing campaign has emerged targeting both corporate and consumer users , spoofing the login portals of OpenAI and Sora . The scammers send well-crafted emails that resemble official service notifications , warning of a supposed account suspension or unusual activity . The attackers’ goal is to trick users into submitting their credentials.

Hacker OpenAI Sora credentials

Phishing tricks

The messages include links to fake pages that replicate SSL certificates and the visuals of the genuine OpenAI and Sora, making the difference indistinguishable even to experienced users. Early reports emerged when organizations detected unauthorized accessimmediately after employees clicked on such decoys. The quality of the messages—with targeted content and social engineering techniques—indicates that the attackers have prepared the campaign in a professional manner.

See also: Pixnapping attack: Malicious Android apps steal 2FA codes

Multi-stage loader and hiding strategy

Security researchers at Unit 42 have identified a multi-stage loader written in obfuscated JavaScript that dynamically injects malicious payloads browsers victims’ collects usernames and passwords and sends them to a command and control (C2) server before redirecting the user to the legitimate service. This tactic acts as a “cover”: it reduces suspicion, as the end user quickly sees the genuine page, while the criminals extract large amounts of credentials from both corporate and personal profiles.

Hackers impersonate OpenAI and Sora to steal credentials

OpenAI and Sora Abuse: Risks and Operational Impact

The impact is critical. Stolen credentials can allow access to sensitive data, be used to manipulate AI models , or launch additional attacks. Particularly vulnerable are systems that rely on Single Sign-On (SSO), where obtaining a token can provide lateral movement within corporate networks and facilitate privilege escalation. The attackers’ ability to remain undetected allows for long-term credential collection and greater damage.

See also: RMPocalypse attack allows AMD SEV-SNP compromise

Recommendations for security teams

Guidance for security teams includes reviewing recent login activity, implementing multi-factor authentication (MFA) where possible, and continuously monitoring outbound traffic for connections to known malicious domains. Additionally, training staff to recognize suspicious emails and social engineering techniques remains critical. Systematic checks for unusual sessions, mismatches in the geographic origin of connections , and rapid credential suspension processes can limit the spread.

Technical details of infection and persistence

The campaign’s core is a JavaScript loader, which is activated immediately after login credentials are submitted to the phishing page. The code appears to be largely obfuscated, with custom string-encoding routines; once decoded, it communicates with C2 endpoints and retrieves complex payloads to execute in the victim’s browser environment. This dynamic loading makes it difficult to detect with traditional signatures, since the actual malicious code is never displayed on the home page. In addition, local storage and session resume scripts are leveraged so that the loader is reactivated even if the user clears cookies or closes the tab.

See also: Russian TwoNet Group Attacks OT/ICS Devices

Hackers impersonate OpenAI and Sora to steal credentials

Practical response steps

Teams must immediately isolate suspicious sessions, revoke stolen tokens, push security updates , and perform forensic analysis to identify the source and extent of the breach. Partnering with identity providers, educating consumers, and sharing breach indicators with Threat Intelligence communities accelerate detection and reduce the success of future campaigns. Responding promptly reduces risk, saves resources, and protects the organization’s reputation.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS