Podcast Detail

SANS Stormcast Friday, October 2nd, 2026: ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10120.mp3

Podcast Logo
ScreenConnect Abuse; ChatGPT Abuse; Spoofing iCloud; Proton Mail display name
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Friday, October 2nd, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from
 Jacksonville, Florida. And this episode is brought to you
 by the SANS.edu Graduate Certificate Program in
 Incident Response. Xavier today is walking us through a
 real simple attack that doesn't require any malware
 and will actually use a legitimate remote admin tool,
 not one of the malicious ones that we often see. In this
 particular case, it uses Screen Connect and this is not
 really a problem with Screen Connect itself. It could have
 been done with many similar tools. So the way these tools
 are often used is to provide remote assistance to users,
 users that are often not very technically versed. And as a
 result, it's easy to set up these tools. So what the
 attacker does here is that they email you a copy of
 Screen Connect, again, a legitimate copy of Screen
 Connect, that includes a configuration that once Screen
 Connect is started will immediately connect with the
 attacker and provide the attacker with remote access to
 the system. So here, replace attacker with tech support,
 and you kind of can see how this is a legitimate feature
 that is quite useful. I've mentioned this before here in
 this podcast, but you must control these remote admin
 tools. Many, many attacks are using legitimate remote admin
 tools. Sometimes they install them on your system. Sometimes
 they do use remote admin tools that they may already find
 installed on your system. So it's not always the ones that
 the attacker installed, but maybe some that you installed
 to help instrument the network for the attacker. And Huntress
 is observing the abuse of OpenAI's custom GPT feature in
 order to deliver phishing messages and essentially
 directing users to click-fix attack. The way this works is
 that OpenAI, at least up to now, has a feature that allows
 you to create what they're calling custom GPTs. So
 instead of sending a user to the default ChatGPT website,
 you send them to a custom version of yours, which is
 still a valid, it's still ChatGPT you're sending them
 to, but this version now comes with a number of additional
 instructions, often used to tailor responses for a
 specific audience or to solve specific types of problems. So
 you can include essentially special prompts and documents
 and such that are being used to create the answer. And
 hackers are using this feature to then deliver back a link to
 the click-fix page, which will then attack the user, well,
 the way click-fix does attack users by making them copy
 -paste strings into the terminal. So from a user point
 of view, that's really hard to detect because you're going to
 a legitimate ChatGPT website. Also sort of from an automatic
 defense point of view, that's also not that easy to figure
 out that you're not going to the default page, but to a
 user-created page. And many of these custom GPTs are useful
 and are definitely something that your users may want to
 experiment with occasionally. Now, I believe that this
 custom GPT feature is actually going away in ChatGPT. So this
 may just be a temporary problem now, but definitely
 something to keep on the radar. And SecConsult did
 publish an interesting blog post with details how it was
 possible to spoof Apple iCloud identities. It's a problem
 that many sort of cloud providers have that they are
 delivering emails for a wide range of users. So they all
 have their own mechanism that you're only able to send email
 for email addresses that are actually assigned to you.
 Similar with iCloud. Now, the other problem, of course,
 then, is that SMTP is, as so many protocols, a little bit
 more flexible than some people sometimes imagine. And one
 feature that's particularly causing issues here is how
 lines are terminated. The standard requires carriage
 return line feed, but by creatively injecting some
 carriage returns without a line feed, you can confuse
 Apple iCloud, or you were able to confuse Apple iCloud as to
 what the actual from header is. And with this, you were
 able to then spoof the from address, essentially send
 email from another iCloud identity than the one assigned
 to you. Another notable issue here, and part of the reason
 why I did mention this particular story is that
 SecConsult was amazingly patient in actually releasing
 the details about this vulnerability. They originally
 reported it to Apple back in 2024, and then after a lot of
 forth and back, well, finally, this issue is now patched.
 There was a similar issue here with ProtonMail. Well, not
 quite sure if it's really similar, but in that case, the
 email spoofing actually used homographs, so basically
 letters that look alike, in particular Unicode letters
 that look alike, in order to impersonate others' names.
 That has not been patched yet, and in my opinion, it's a
 lesser issue in some ways, because while you're still
 presenting what was supposed to show up there, it's just
 sort of the nature of Unicode that you have multiple letters
 that look alike. Well, and that's it for today. Any CRDs
 can wait till Monday, turn off your IDS alerts on the
 weekend, so you won't get bothered by any of them, and
 we'll talk to you again on Monday. Bye.