ChatGPT 4.0: A marketplace for stolen Premium accounts

From in December of 2022, Check Point Research (CPR) has expressed concerns about the consequences of ChatGPT at cyber security. Now, CPR is warning that there is an increase in the trade of stolen ChatGPT Premium accounts, which allow cybercriminals to bypass OpenAI's geofencing restrictions and gain unrestricted access to ChatGPT.

The market of ATOs (account takeovers), of stolen accounts on different online services, is one of the most thriving markets in the hacking underground and dark web. Traditionally, the market she aimed on stolen financial services accounts (banks, online payment systems, etc.), social media, online dating sites, emails, and more.

chatgpt jpg

As of March 2023, CPR is seeing an increase in chat and trade of stolen ChatGPT accounts, with a focus on Premium accounts:

  1. Leaking and free posting of credentials to ChatGPT accounts
  2. Stolen ChatGPT premium account transactions
  3. Bruteforcing and Checkers tools for ChatGPT – which allow cybercriminals to break into ChatGPT accounts by running through huge lists of email addresses and passwords, trying to guess the correct combination to access existing accounts.
  4. ChatGPT Accounts as a Service – a special service offering to open premium ChatGPT accounts, possibly using stolen payment cards.

Why is the market for stolen ChatGPT accounts growing and what are the main concerns?

As we wrote previously histology, the ChatGPT imposes geographic restrictions on access to of certain countries (including Russia, China and Iran). Recently we stressed that using the ChatGPT API; it allows cybercriminals to bypass different restrictions as well the use of your ChatGPT premium account.

All this leads to a growing demand for stolen ChatGPT accounts, especially paid premium accounts. In the dark websites, όπου υπάρχει ζήτηση - υπάρχουν έξυπνοι cybercriminals ready to take advantage of the business opportunity.

Meanwhile, in recent weeks there have been discussions about ChatGPT's privacy issues, with Italy to forbid it and Germany to consider a similar possibility. We highlight one more potential privacy risk of this platform. ChatGPT accounts store the account holder's recent queries. So when cybercriminals steal existing accounts, they gain access to the original owner's queries. This may include personal information, details about company products and processes and more.

Trade stolen accounts of Chat GPT

Cybercriminals often take advantage of the fact that users recycle the same password across multiple platforms. Using this knowledge, they load sets of email and password combinations into a special software (also known as account control) and perform an attack against a specific online platform to find the sets of credentials that match the login to the platform.

A final account takeover occurs when a malicious actor takes control of an account without the account owner's authorization.

Over the past month, CPR has noticed an increase in discussions on underground forums related to the leaking or sale of compromised ChatGPT premium accounts:

111111

Image 1 - Threads in underground forums around stolen ChatGPT accounts

The stolen accounts are mostly sold, but some of the cybercriminals also share stolen ChatGPT premium accounts for free, to advertise their own services or tools to steal the accounts. In the example below, one shared four stolen premium ChatGPT accounts. The way they were shared and their structure led CPR to conclude they were stolen using a ChatGPT account controller.

222222
33333

Image 2 – Cybercriminal sharing four premium ChatGPT accounts for free

Εργαλεία για να χακάρετε λογαριασμούς ChatGPT - Έλεγχος λογαριασμού και configuration for Bruteforcing tools

SilverBullet is one websites test suite that allows users to run requests to a targeted web application. It offers many tools to work with . This software can be used for collection and data analysis, automated pen testing, unit testing through selenium and more. This tool is also often used by cybercriminals to conduct credential stuffing and account control attacks against different websites and thus steal accounts for online platforms.

Καθώς το SilverBullet είναι μια διαμορφώσιμη σουίτα, για να κάνετε έναν έλεγχο ή μια βίαιη επίθεση εναντίον ενός συγκεκριμένου ιστότοπου απαιτεί ένα αρχείο "διαμόρφωσης" που προσαρμόζει αυτήν τη διαδικασία για έναν συγκεκριμένο ιστότοπο και επιτρέπει στους εγκληματίες του κυβερνοχώρου να κλέψουν λογαριασμό αυτού του ιστότοπου με αυτοματοποιημένο τρόπο.

In this particular case, CPR identified cybercriminals offering a configuration file for SilverBullet that allows a set of credentials for OpenAI's platform to be checked in an automated manner. This allows them to steal accounts at scale. The process is fully automated and can start from 50 to 200 checks per minute (CPM). It also supports a proxy application that in many cases allows it to bypass different protections on websites from such attacks.

44444

Image 3 - Κυβερνοεγκληματίας που προσφέρει αρχείο διαμόρφωσης openAI για το SilverBullet

Ένας άλλος κυβερνοεγκληματίας που επικεντρώνεται μόνο στην κατάχρηση και την απάτη κατά των προϊόντων του ChatGPT, ονόμασε ακόμη και τον εαυτό του "gpt4". Στα threads of, offers for sale not only ChatGPT accounts but also a configuration for another automated tool that checks the validity of a credential.

5555555
66666

Image 4 - Ο εγκληματίας στον κυβερνοχώρο που ονομάζεται "gpt4" προσφέρει διαφορετικές υπηρεσίες που σχετίζονται με κατάχρηση γύρω από την πλατφόρμα

ChatGPT Plus lifetime upgrade service

On March 20, an English-speaking cybercriminal started advertising an account service Chat GPT More Lifetime, with 100% satisfaction guaranteed.

A lifetime upgrade to the regular ChatGPT Plus account (opened via email provided by the buyer) costs $59.99 (while OpenAI's initial legal pricing for this service is $20 per month). However, to keep costs down, this underground service also offers the option to share access to your ChatGPT account with another cybercriminal for $24.99, for life.

Some underground users have already left positive feedback for this service and vouched for it.

As in other illegal situations, when the threat actor provides certain services for pricing that is significantly lower than the original legitimate (for another example, see blog our on underground travel ticket services), we assess that payment for the upgrade is made using previously violationspaid payment cards.

88888
99999

 

Image 5 – ChatGPT Plus lifetime account underground service

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
ChatGPT4

Written by newsbot

Although the press releases will be from very select to rarely, I said to go ... because sometimes the authors are hiding.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).