Two pulses published to AlienVault OTX on 2026-10-05 converge on a single, uncomfortable truth for enterprise defenders: the credential and secrets economy is being fed from both ends — mass-market social engineering against end users, and targeted insider-style betrayal against the RaaS ecosystem itself.
Pulse 1 — ClickFix via ChatGPT Custom GPTs. Threat actors are abusing ChatGPT's Custom GPT feature to impersonate legitimate OpenAI models. Sponsored Google ads funnel victims to malicious Custom GPTs branded 'Plus 5.6', which display fake service-availability notices and redirect to Google Sites pages hosting ClickFix lures disguised as Cloudflare CAPTCHA checks. Victims are socially engineered into pasting and executing attacker-supplied PowerShell commands. The payload ecosystem observed in this campaign spans Matanbuchus, AstarionRAT, AMOS (macOS Atomic Stealer lineage), MacSync, SectopRAT, Lumma Stealer, and the legitimate-but-abused screen recorder GOMCam — a classic dual-platform (Windows/macOS) infostealer and RAT distribution operation with a clear credential-theft objective. The pulse also tags Stardock software abuse and DNS-over-HTTPS (DoH) for C2 concealment.
Pulse 2 — 'Caught in 4K: The Gentlemen Files.' A Russian-speaking affiliate of the Gentlemen ransomware group, operating as Azazel, compromised more than two dozen organizations across six countries — spanning logistics, finance, healthcare, technology, and government — while simultaneously betraying the RaaS operator by standing up an independent leak site, LEAKNED, and pocketing all extortion proceeds. Attack chains primarily exploited CI/CD secrets harvested from GitLab instances; at least one deep compromise involved an AI platform / MCP environment. The infrastructure forgitlab.com (66.179.30.155) was used to impersonate GitLab services — almost certainly for phishing developers and DevOps staff or for trojanized GitLab tooling to siphon pipeline secrets.
The synthesis: both campaigns monetize the same asset class — credentials and secrets. ClickFix steals browser/session credentials at scale; Azazel steals CI/CD tokens, deploy keys, and cloud secrets that yield far deeper, persistent enterprise compromise. A stolen GitLab PAT is worth more than a thousand browser passwords. Security teams must treat these as one threat surface: identity and secret material.
Threat Actor / Malware Profile
Lumma Stealer (LummaC2)
- Distribution: ClickFix fake CAPTCHA, malvertising, trojanized software.
- Payload behavior: Browser credential/cookie/session-token theft (Chrome, Edge, Firefox), crypto wallet exfiltration, 2FA extension targeting, exfil via HTTPS to C2 panels.
- C2: HTTPS to rotating panel domains; increasingly tunnels via DNS-over-HTTPS (Cloudflare/Google DoH resolvers) to evade DNS-layer detection.
- Persistence: Run keys, scheduled tasks masquerading as browser update jobs.
- Anti-analysis: VM/sandbox checks, string obfuscation, code delivered as Base64 PowerShell stagers.
Matanbuchus
- Distribution: ClickFix PowerShell execution, malspam loaders.
- Payload behavior: Loader-as-a-service; executes in-memory PowerShell and .NET payloads, hands off to secondary RATs/stealers (consistent with the AstarionRAT/SectopRAT co-occurrence in this pulse).
- C2: HTTPS with hardcoded fallback domains; anti-analysis via environment checks and delayed execution.
SectopRAT (ArechClient2)
- Behavior: .NET RAT establishing a hidden secondary desktop session for covert browser interaction — purpose-built for session hijacking and credential abuse without visible user disturbance. C2 over TLS, often proxied through legitimate services.
AMOS / MacSync (macOS)
- Distribution: Same ClickFix lures adapted for macOS (fake CAPTCHA instructing Terminal paste).
- Behavior: Keychain theft, browser credential extraction, iCloud/session token harvesting; exfil over HTTPS.
Gentlemen RaaS / Azazel (Affiliate)
- Access vector: Compromised GitLab CI/CD secrets — personal access tokens, CI job tokens, deploy keys, exposed
.envand pipeline variables — enabling lateral movement into production, cloud, and SaaS estates. Lookalike domainforgitlab.comsupports developer-targeted phishing. - Post-compromise: Double extortion — data exfiltration precedes encryption; independent leak site LEAKNED used to pressure victims while cutting out the RaaS operator. One victim environment included an AI platform with MCP (Model Context Protocol) integrations — an emerging high-value target given MCP servers frequently hold broad API credentials.
- Defense evasion: Legitimate tooling (GOMCam for surveillance staging), living-off-the-cloud exfiltration.
IOC Analysis
Indicator composition across the two pulses:
- 48 indicators (Pulse 1) are dominated by file hashes (SHA-256 and MD5) representing ClickFix PowerShell stagers, Matanbuchus loaders, Lumma samples, and RAT payloads. Hashes are brittle — the ClickFix model generates per-victim payloads — but remain essential for retro-hunts across EDR telemetry and for confirming whether a user actually executed the staged payload versus merely visiting the lure.
- 2 indicators (Pulse 2) are network-based: IPv4
66.179.30.155and domainforgitlab.com. These are high-value: a single DNS lookup or TLS session to this infrastructure from a developer workstation or CI runner is a probable GitLab-credential-phishing compromise and should trigger secret rotation immediately.
Operationalization guidance for SOC teams:
- Hashes → retro-hunt, not just block. Load all SHA-256/MD5 values into your EDR's hash-search and sweep 90 days of process/file telemetry. ClickFix payloads are short-lived; presence of any hash indicates completed execution, not just exposure.
- Domain/IP → network interdiction + identity response. Block
forgitlab.comand66.179.30.155at DNS, proxy, and egress firewall. Then pivot: any host resolving or connecting to these indicators must have its GitLab tokens, SSH keys, and CI variables assumed compromised. - DoH detection. Because this campaign uses DNS-over-HTTPS for C2, standard DNS sinkholing will miss it. Monitor for DoH endpoint usage (dns.google, cloudflare-dns.com, mozilla.cloudflare-dns.com) from endpoints and servers that have no business bypassing internal resolvers.
- Tooling: Decode ClickFix PowerShell stagers with CyberChef (Base64 + common XOR); detonate hashes in ANY.RUN or Triage; enrich infrastructure in OTX, VirusTotal, and urlscan.io. Cross-check GitLab access logs against the phishing window for anomalous token creation.
Detection Engineering
---
title: ClickFix Fake CAPTCHA PowerShell Execution (Lumma/Matanbuchus Delivery)
id: 3f9a2c1e-7b44-4d21-9a1c-clickfix001
status: experimental
description: Detects PowerShell execution consistent with ClickFix social-engineering lures delivering infostealers (Lumma, Matanbuchus, SectopRAT) via malicious Custom GPTs and fake Cloudflare CAPTCHA pages.
author: Security Arsenal Threat Intelligence
references:
- https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
date: 2026/10/05
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
selection_encoded:
CommandLine|contains:
- ' -enc '
- ' -ec '
- 'EncodedCommand'
- 'FromBase64String'
selection_download:
CommandLine|contains:
- 'Invoke-WebRequest'
- 'Invoke-RestMethod'
- 'iwr '
- 'irm '
- 'curl.exe'
- 'DownloadString'
- 'Start-BitsTransfer'
selection_clipboard:
CommandLine|contains:
- 'Get-Clipboard'
- 'Set-Clipboard'
condition: selection_img and (selection_encoded or (selection_download and selection_clipboard))
falsepositives:
- Rare legitimate admin automation combining clipboard and download cradles
level: high
tags:
- attack.t1059.001
- attack.t1204.002
- attack.t1105
---
title: Endpoint DNS-over-HTTPS Usage Bypassing Internal Resolver
id: 8d2b4f77-1c93-4e55-b2d2-doh002
status: experimental
description: Detects outbound HTTPS connections to public DNS-over-HTTPS resolvers from endpoints, a C2 concealment technique used by Lumma Stealer and Matanbuchus in the ClickFix campaign.
author: Security Arsenal Threat Intelligence
date: 2026/10/05
logsource:
category: network_connection
product: windows
detection:
selection_doh_dest:
DestinationHostname|contains:
- 'dns.google'
- 'cloudflare-dns.com'
- 'mozilla.cloudflare-dns.com'
- 'dns.quad9.net'
- 'doh.opendns.com'
selection_doh_ip:
DestinationIp:
- '1.1.1.1'
- '1.0.0.1'
- '8.8.8.8'
- '8.8.4.4'
DestinationPort: 443
filter_browsers:
Image|endswith:
- '\chrome.exe'
- '\firefox.exe'
- '\msedge.exe'
condition: (selection_doh_dest or selection_doh_ip) and not filter_browsers
falsepositives:
- Browser DoH configuration (filtered); developer tooling with explicit DoH
level: medium
tags:
- attack.t1071.001
- attack.t1572
---
title: GitLab Phishing Infrastructure or CI/CD Secret Access Anomaly (Azazel / Gentlemen)
id: b71c9a03-55e1-4f88-c3a3-gitlab003
status: experimental
description: Detects network connections to GitLab-impersonating infrastructure associated with the Gentlemen ransomware affiliate Azazel and suspicious access to CI/CD secret stores.
author: Security Arsenal Threat Intelligence
references:
- https://www.cloudsek.com/blog/caught-in-4k-the-gentlemen-files
date: 2026/10/05
logsource:
category: network_connection
detection:
selection_infra:
DestinationHostname|contains:
- 'forgitlab.com'
DestinationIp:
- '66.179.30.155'
condition: selection_infra
falsepositives:
- None expected; forgitlab.com is attacker-controlled lookalike infrastructure
level: critical
tags:
- attack.t1552.004
- attack.t1566
- attack.t1567
// Hunt: ClickFix execution, DoH C2, and GitLab phishing infrastructure — OTX 2026-10-05
let lookback = 14d;
let bad_hashes_sha256 = dynamic([
"22869e3326fe1de011cd500e666769027126c5c440b76837baf55139f30094e4",
"0457414c4504b70115798eee9c8384a8bf9e793461ffb2e0661a6dcc6ed4809f",
"14e3376befd4b7b52de0757b6264da294ac6b0f9e4ff51cb9bc5b19b243fe335",
"20c7befc174a61117770535e809046c75e93c71284bf1a9c6cd532f55b315f53",
"278e2f3e2f26c18666b89ef774b4af9ce954e36b2bf54a2392608619245d8c48",
"3cd1484cc5bf10e22d79784beba58a75d7b126c46efb5e1a85d6aab884447621"]);
let bad_hashes_md5 = dynamic(["6ab595ad6554819181b686d4876efb80", "6ab6ba039440819185ed491740b11cf8"]);
// 1) ClickFix-style PowerShell: encoded commands + download/clipboard cradles
let ClickFix = DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName in~ ("powershell.exe","pwsh.exe")
| where ProcessCommandLine has_any ("-enc","EncodedCommand","FromBase64String")
or (ProcessCommandLine has_any ("Invoke-WebRequest","irm ","iwr ","DownloadString","curl.exe")
and ProcessCommandLine has "Get-Clipboard")
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine;
// 2) Hash matches for known ClickFix payload hashes
let HashHits = DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where SHA256 in~ (bad_hashes_sha256) or MD5 in~ (bad_hashes_md5)
| project TimeGenerated, DeviceName, AccountName, FileName, FolderPath, SHA256, MD5;
// 3) Network: Azazel GitLab phishing infra + suspicious DoH from non-browser processes
let NetworkHits = DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where RemoteUrl has "forgitlab.com" or RemoteIP == "66.179.30.155"
or (RemoteUrl has_any ("dns.google","cloudflare-dns.com","mozilla.cloudflare-dns.com")
and InitiatingProcessFileName !in~ ("chrome.exe","firefox.exe","msedge.exe"))
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort;
union ClickFix, HashHits, NetworkHits
| order by TimeGenerated desc
# Security Arsenal - IOC Hunt: ClickFix Infostealer + Azazel/Gentlemen Artifacts
# OTX Pulses 2026-10-05 | Run elevated on Windows endpoints
$report = @()
# --- 1) Hash sweep: known ClickFix / Lumma / Matanbuchus payload hashes ---
$badHashes = @(
'22869e3326fe1de011cd500e666769027126c5c440b76837baf55139f30094e4',
'0457414c4504b70115798eee9c8384a8bf9e793461ffb2e0661a6dcc6ed4809f',
'14e3376befd4b7b52de0757b6264da294ac6b0f9e4ff51cb9bc5b19b243fe335',
'20c7befc174a61117770535e809046c75e93c71284bf1a9c6cd532f55b315f53',
'278e2f3e2f26c18666b89ef774b4af9ce954e36b2bf54a2392608619245d8c48',
'3cd1484cc5bf10e22d79784beba58a75d7b126c46efb5e1a85d6aab884447621'
)
$searchPaths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","$env:USERPROFILE\Downloads","$env:ProgramData")
foreach ($p in $searchPaths) {
Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue |
Where-Object { $_.Length -lt 50MB } | ForEach-Object {
$h = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
if ($badHashes -contains $h.ToLower()) {
$report += [PSCustomObject]@{Type='HashMatch'; Path=$_.FullName; Detail=$h}
}
}
}
# --- 2) Persistence: Run keys masquerading as browser/system updaters (Lumma/Matanbuchus) ---
$runKeys = @('HKCU:\Software\Microsoft\Windows\CurrentVersion\Run',
'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run')
foreach ($rk in $runKeys) {
Get-ItemProperty $rk -ErrorAction SilentlyContinue | ForEach-Object {
$_.PSObject.Properties | Where-Object {
$_.Value -match 'powershell|mshta|rundll32|AppData|Temp' -and $_.Name -notmatch '^PS'
} | ForEach-Object {
$report += [PSCustomObject]@{Type='RunKey'; Path="$rk\$($_.Name)"; Detail=$_.Value}
}
}
}
# --- 3) Scheduled tasks staging from user-writable paths ---
Get-ScheduledTask | ForEach-Object {
$actions = $_.Actions | ForEach-Object { "$($_.Execute) $($_.Arguments)" }
if (($actions -join ' ') -match 'AppData|Temp|powershell.*-enc|mshta') {
$report += [PSCustomObject]@{Type='ScheduledTask'; Path=$_.TaskName; Detail=($actions -join '; ')}
}
}
# --- 4) Network: Azazel GitLab phishing infra + active DoH connections ---
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue | Where-Object {
$_.RemoteAddress -eq '66.179.30.155' -or
($_.RemotePort -eq 443 -and $_.RemoteAddress -in @('1.1.1.1','1.0.0.1','8.8.8.8','8.8.4.4'))
} | ForEach-Object {
$proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
$report += [PSCustomObject]@{Type='NetConnection'; Path=$proc.Path; Detail="$($_.RemoteAddress):$($_.RemotePort) via $($proc.Name)"}
}
# --- 5) DNS cache check for forgitlab.com ---
Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object { $_.Entry -match 'forgitlab\.com' } |
ForEach-Object { $report += [PSCustomObject]@{Type='DNSCache'; Path=$_.Entry; Detail=$_.Data} }
$report | Format-Table -AutoSize
if ($report) { $report | Export-Csv ".\OTX_Hunt_$(Get-Date -Format 'yyyyMMdd_HHmm').csv" -NoTypeInformation; Write-Host "[ALERT] $($report.Count) findings exported." -ForegroundColor Red }
else { Write-Host "[CLEAN] No indicators found." -ForegroundColor Green }
Response Priorities
Immediate (0–4 hours):
- Block
forgitlab.comand66.179.30.155at DNS, secure web gateway, and egress firewall; add all 48 file hashes to EDR blocklists. - Deploy the Sigma and KQL detections above; retro-hunt 90 days of process and network telemetry for ClickFix PowerShell patterns (encoded commands, clipboard-read cradles) and DoH from non-browser processes.
- Query IdP and email logs for users who clicked sponsored Google ads referencing 'Plus 5.6' Custom GPTs or fake CAPTCHA pages; force-reset credentials for any user whose device shows a hash or execution match — assume browser session tokens are stolen and revoke active sessions, not just passwords.
24 hours:
- If any endpoint shows infostealer execution: invalidate all cookies/sessions for that user across SSO, SaaS, and VPN; reset credentials from a clean device; review MFA enrollment changes.
- Audit GitLab (and all CI/CD platforms): enumerate personal access tokens, deploy keys, and CI/CD variables created or used in the last 30 days; rotate any secret touched by developer workstations that resolved
forgitlab.com. Review GitLab audit logs for token creation from unfamiliar IPs or geographies. - Check macOS fleet for Terminal-based paste-and-run events consistent with AMOS/MacSync ClickFix lures; rotate Keychain-protected credentials on confirmed hits.
1 week:
- Harden the CI/CD control plane: enforce short-lived OIDC-based credentials instead of static tokens, restrict CI variable exposure to protected branches, enable secret-scanning push protection, and require phishing-resistant MFA (FIDO2) for all developer accounts.
- Constrain DoH: block public DoH resolvers at egress for non-browser processes and enforce internal DNS; alert on bypass attempts.
- ClickFix resilience: restrict PowerShell for standard users (Constrained Language Mode, AppLocker/WDAC), enable clipboard-access browser policies where feasible, and run user awareness specifically on the 'paste this command to prove you're human' lure pattern.
- AI platform governance: inventory MCP servers and Custom GPT usage; audit what credentials AI agents hold and scope them to least privilege — Azazel's AI-platform compromise demonstrates these integrations are now extortion-grade targets.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.