Phishing Emails Impersonate ChatGPT to Steal Account Credentials

· Original article ↗

Summary

Cofense identified a fake ChatGPT subscription invoice that uses urgency and a Google API redirect to send users to a lookalike login page, where entered credentials are stolen.

Key points

  • The phishing email claims a subscription payment needs updating and pressures recipients to act within 48 hours.
  • It uses the real ChatGPT logo and OpenAI branding, but comes from a non-OpenAI address.
  • The payment button uses a Google API redirect that leads to a lookalike ChatGPT login page hosted at e83cedb076[.]nxcli[.]io.
  • Credentials entered on the fake page are sent to the attacker; the victim is then redirected to an error page.
  • Check the sender address and confirm the login domain is auth[.]openai[.]com before entering credentials.

Article Details

Event Type
Phishing email impersonating a ChatGPT subscription payment notice
Impact
The phishing page was designed to steal OpenAI account credentials and payment information. Cofense reports that credentials entered on the page were sent to the attacker, but does not report a confirmed number of affected accounts.

Indicators of compromise

TypeIndicatorContext
EMAILsupport@9527db6e1a[.]nxcli[.]ioSender address used for the fraudulent subscription invoice email.
URLhxxps[:]//e83cedb076[.]nxcli[.]io/fertaq/app/key[.]phpObserved payload URL for the phishing attempt.
URLhxxps[:]//e83cedb076[.]nxcli[.]io/fertaq/app/login[.]phpObserved payload URL for the phishing attempt.

MITRE ATT&CK

Products

Related Articles