Skip to content

Add detection rule for OpenAI ChatGPT Ads impersonation#4709

Open
peterdj45 wants to merge 2 commits into
mainfrom
peter.new.brand_impersonation_chatgptads
Open

Add detection rule for OpenAI ChatGPT Ads impersonation#4709
peterdj45 wants to merge 2 commits into
mainfrom
peter.new.brand_impersonation_chatgptads

Conversation

@peterdj45

Copy link
Copy Markdown
Member

This rule detects messages impersonating OpenAI or ChatGPT, specifically targeting references to ChatGPT Ads and potential credential harvesting attempts.
@peterdj45 peterdj45 requested a review from a team June 22, 2026 19:25
@peterdj45 peterdj45 requested a review from a team as a code owner June 22, 2026 19:25
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Jun 22, 2026
github-actions Bot added a commit that referenced this pull request Jun 22, 2026
github-actions Bot added a commit that referenced this pull request Jun 22, 2026
@peterdj45

peterdj45 commented Jun 22, 2026

Copy link
Copy Markdown
Member Author

Hunts look good, observed several variations of this campaign.

L90D Shared EML: https://platform.sublime.security/messages/hunt?huntId=019ef0b7-ad2b-7542-8138-8c09d5e6454f

Multi-hunt results in ESC-15733

@peterdj45 peterdj45 added the review-needed Indicates that a PR is waiting for review label Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant