Threat actors are using legitimate ChatGPT shared-conversation URLs in a ClickFix campaign that presents Windows users with a fake availability warning and directs them to a fraudulent backup site. Neither ChatGPT nor OpenAI infrastructure was compromised. The lure persuades victims to open the Windows Run dialog and execute a clipboard-copied PowerShell command, which downloads and runs remote content associated with brmconfig.com; openai-backup.one and a masqueraded video.mp4 resource are also linked to the delivery chain.
The multi-stage loader profiles the host and sends device, public-IP, network, and geolocation data to attacker-controlled Telegram infrastructure before retrieving a legitimate MP4 file containing an encrypted PowerShell bundle. The bundle reportedly embeds 20 files, including a signed NetSupport remote-control client that can provide unauthorized remote access and monitoring. The malware hides consoles, checks for analysis-related hostnames, bypasses PowerShell execution policy, clears the Windows RunMRU history, and may leave artifacts under ProgramData, complicating detection and forensic review.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
A malicious ClickFix campaign used a legitimate ChatGPT shared-conversation URL to direct Windows users to an OpenAI-themed fake backup site, where a clipboard-copied PowerShell command fetched a multi-stage loader from brmconfig.com. The loader profiled victims, sent telemetry to a Telegram chat, retrieved an MP4 concealing an encrypted PowerShell bundle, and deployed a signed NetSupport remote-control client; ChatGPT and OpenAI infrastructure were not compromised.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.