A campaign built around legitimate shared ChatGPT pages shows how attackers can turn familiar interfaces into a route for NetSupport RAT without touching the platform itself.
Fake Google and Cloudflare-style checks are being used as trust lures in a ClickFix chain that reportedly delivered multiple malware families, including StealC and NetSupport.
ClickFix lures that impersonate Google and Cloudflare turn a routine browser check into a user-driven launchpad for stealers, loaders, and remote-access malware.