DKDKCISSPSearch
AI SecurityDEVELOPING

Sentinel Envelope Plus adds software protection without source code changes - Help Net Security

Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation.

DKCISSP News DeskHelp Net Security1 Oct 2026, 1:08 pm
Sentinel Envelope Plus adds software protection without source code changes - Help Net Security
Image courtesy of Help Net Security. Original report
DKCISSP REPORT

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

The two Custom GPT links are listed below - Users who end up interacting with the Custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain." To nudge unsuspecting users into opting for the latter option, the notice also displays the message: "We recommend using the backup domain if you need immediate access." Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command.

Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.

With this expansion, each account gets: Essentials, Advantage, and Elite enterprise customers can extend this offering to include an expanded number of RSS feeds, access to Cloudforce One’s proprietary threat intelligence datasets, the ability to generate custom agentic skills, higher storage options for Threat Signals’ derived open-source reporting, and the ability to create custom WAF rules on open-source and proprietary threat events.

This link directs the user to a malicious Microsoft Software Installer (MSI) which is used to deploy a legitimate Canon-signed application the attackers have used to sideload malicious code, this ultimately establishes persistence on the machine and delivers remote access trojan (RAT) malware .

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

However, the company also noted, “Supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.” To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:

By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems.

The analysis also reveals that threat groups are reusing tools and techniques , introducing new attack models, exploiting vulnerabilities and collaborating to target the security and resilience of the EU’s digital infrastructure.

Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation.

What happened

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

The two Custom GPT links are listed below - Users who end up interacting with the Custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain." To nudge unsuspecting users into opting for the latter option, the notice also displays the message: "We recommend using the backup domain if you need immediate access." Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command.

What changed

Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.

With this expansion, each account gets: Essentials, Advantage, and Elite enterprise customers can extend this offering to include an expanded number of RSS feeds, access to Cloudforce One’s proprietary threat intelligence datasets, the ability to generate custom agentic skills, higher storage options for Threat Signals’ derived open-source reporting, and the ability to create custom WAF rules on open-source and proprietary threat events.

Who is affected

This link directs the user to a malicious Microsoft Software Installer (MSI) which is used to deploy a legitimate Canon-signed application the attackers have used to sideload malicious code, this ultimately establishes persistence on the machine and delivers remote access trojan (RAT) malware .

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

Why it matters

However, the company also noted, “Supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.” To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:

By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems.

Technical details

The analysis also reveals that threat groups are reusing tools and techniques , introducing new attack models, exploiting vulnerabilities and collaborating to target the security and resilience of the EU’s digital infrastructure.

Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation.

Many teams that need strong endpoint protection standardize on Microsoft Defender plus Huntress Managed EDR, a combination that brings purpose-built EDR technology, low-noise detections, and SOC-driven remediation without the operational weight of full allowlisting.

Response

ClickFix is a hybrid of browser and endpoint targeting — the lure is delivered via the browser, but the user copies and runs malicious scripts locally, typically installing Remote Access Tools or infostealer malware.

Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.

What security teams should do

For more detail on each of these attack techniques, how they work in the wild, and what you can do about them, check out the guide to 2026 Browser Attack Techniques from Push Security .

The 2026 ENISA Threat Landscape confirms that cyber dependencies expand the attack surface and require a new level of vigilance to effectively prevent and mitigate the impact of cyber incidents.

What remains unknown

While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.

Attribution

Help Net Security: Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation.

Help Net Security: A junior analyst in a security operations center, or SOC, has usually learned the job the slow way.

Huntress: Agent Tesla is a remote access trojan (RAT) first identified as spyware capable of stealthily capturing and exfiltrating a wide array of data from victims’ systems.

Huntress: But if you're running ThreatLocker, that's where a chunk of your week goes, writing policies, tuning exceptions, figuring out why a legitimate app got blocked at 4pm on a Friday.

What to watch next

Watch for updated vendor guidance and fixed-version details.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am