Skip to main content


Sophos has observed malicious advertisements targeting ChatGPT users ⚠️​

1️⃣​ Google search for "chat gpt"
2️⃣​​ Google Ad Click Redirect to fake ChatGPT website 🎣​​"eicnhdcb[.]online"
3️⃣​​ File download via transher[.]sh
➡️​ ChatGPT.zip\chatgpt.exe

#IOCs: https://www.virustotal.com/gui/file/db0270b977bf68fb8ce2e161bae88c7dd4ed82866b3bbc3d6c8a713edc69db53/relations
#InfoStealer C2: 45.93.201.114
🔗​ https://urlscan.io/result/f7bcab56-71c6-45ac-930a-adb057467920

#CTI #ThreatIntel #malvertising
Fake OpenAI website used to download infostealler malware
This entry was edited (1 year ago)