Handler on Duty: Xavier Mertens
Threat Level: green
Podcast Detail
SANS Stormcast Friday, October 2nd, 2026: ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10120.mp3
My Next Class
Click HERE to learn more about classes Johannes is teaching for SANS
ScreenConnect Client (Ab)used by Attackers
https://isc.sans.edu/diary/ScreenConnect+Client+Abused+by+Attackers/33388/#comments
Attackers abuse ChatGPT to deliver RAT via ClickFix
https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat?_sp=51406044-aa1d-4278-a4e7-adb5b8ef84b2.1790890760100
Spoofing iCloud From Address
https://sec-consult.com/blog/detail/from-anyoneicloudcom-spoofing-arbitrary-apple-icloud-identities/
Sender spoofing in Proton Mail via display-name homograph
https://alonsovidales.github.io/protonmail-sender-spoofing/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
| Network Monitoring and Threat Detection In-Depth | Amsterdam | Oct 12th - Oct 17th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Washington | Dec 14th - Dec 18th 2026 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Eastern | Feb 8th - Feb 12th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | India Standard Time | Mar 15th - Mar 19th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Orlando | Apr 12th - Apr 16th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Online | US Mountain | Apr 21st - Apr 25th 2027 |
| Application Security: Securing Web Applications, APIs, and Microservices | Baltimore | May 17th - May 21st 2027 |
Podcast Transcript
Hello and welcome to the Friday, October 2nd, 2026 edition of the SANS Internet Storm Center's Stormcast. My name is Johannes Ullrich, recording today from Jacksonville, Florida. And this episode is brought to you by the SANS.edu Graduate Certificate Program in Incident Response. Xavier today is walking us through a real simple attack that doesn't require any malware and will actually use a legitimate remote admin tool, not one of the malicious ones that we often see. In this particular case, it uses Screen Connect and this is not really a problem with Screen Connect itself. It could have been done with many similar tools. So the way these tools are often used is to provide remote assistance to users, users that are often not very technically versed. And as a result, it's easy to set up these tools. So what the attacker does here is that they email you a copy of Screen Connect, again, a legitimate copy of Screen Connect, that includes a configuration that once Screen Connect is started will immediately connect with the attacker and provide the attacker with remote access to the system. So here, replace attacker with tech support, and you kind of can see how this is a legitimate feature that is quite useful. I've mentioned this before here in this podcast, but you must control these remote admin tools. Many, many attacks are using legitimate remote admin tools. Sometimes they install them on your system. Sometimes they do use remote admin tools that they may already find installed on your system. So it's not always the ones that the attacker installed, but maybe some that you installed to help instrument the network for the attacker. And Huntress is observing the abuse of OpenAI's custom GPT feature in order to deliver phishing messages and essentially directing users to click-fix attack. The way this works is that OpenAI, at least up to now, has a feature that allows you to create what they're calling custom GPTs. So instead of sending a user to the default ChatGPT website, you send them to a custom version of yours, which is still a valid, it's still ChatGPT you're sending them to, but this version now comes with a number of additional instructions, often used to tailor responses for a specific audience or to solve specific types of problems. So you can include essentially special prompts and documents and such that are being used to create the answer. And hackers are using this feature to then deliver back a link to the click-fix page, which will then attack the user, well, the way click-fix does attack users by making them copy -paste strings into the terminal. So from a user point of view, that's really hard to detect because you're going to a legitimate ChatGPT website. Also sort of from an automatic defense point of view, that's also not that easy to figure out that you're not going to the default page, but to a user-created page. And many of these custom GPTs are useful and are definitely something that your users may want to experiment with occasionally. Now, I believe that this custom GPT feature is actually going away in ChatGPT. So this may just be a temporary problem now, but definitely something to keep on the radar. And SecConsult did publish an interesting blog post with details how it was possible to spoof Apple iCloud identities. It's a problem that many sort of cloud providers have that they are delivering emails for a wide range of users. So they all have their own mechanism that you're only able to send email for email addresses that are actually assigned to you. Similar with iCloud. Now, the other problem, of course, then, is that SMTP is, as so many protocols, a little bit more flexible than some people sometimes imagine. And one feature that's particularly causing issues here is how lines are terminated. The standard requires carriage return line feed, but by creatively injecting some carriage returns without a line feed, you can confuse Apple iCloud, or you were able to confuse Apple iCloud as to what the actual from header is. And with this, you were able to then spoof the from address, essentially send email from another iCloud identity than the one assigned to you. Another notable issue here, and part of the reason why I did mention this particular story is that SecConsult was amazingly patient in actually releasing the details about this vulnerability. They originally reported it to Apple back in 2024, and then after a lot of forth and back, well, finally, this issue is now patched. There was a similar issue here with ProtonMail. Well, not quite sure if it's really similar, but in that case, the email spoofing actually used homographs, so basically letters that look alike, in particular Unicode letters that look alike, in order to impersonate others' names. That has not been patched yet, and in my opinion, it's a lesser issue in some ways, because while you're still presenting what was supposed to show up there, it's just sort of the nature of Unicode that you have multiple letters that look alike. Well, and that's it for today. Any CRDs can wait till Monday, turn off your IDS alerts on the weekend, so you won't get bothered by any of them, and we'll talk to you again on Monday. Bye.





