Custom ChatGPTs push ClickFix attacks to deploy RAT malware

by · BleepingComputer

Custom variants of OpenAI’s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.

The threat actor is abusing the legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task that combines instructions, extra knowledge, and skills.

OpenAI hosts these custom GPTs, which can be published for others to install and use. The company plans to retire custom GPTs on December 11.

The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.

The threat actor named the malicious GPT model 'Plus 5.6' and configured it to direct users to an alleged backup site hosted on Google Sites.

The malicious custom GPT
Source: Huntress

However, the page shows a fake Cloudflare check and instructs visitors to run a PowerShell command, which deploys the infection chain.

Huntress researchers observed similar attacks in the past, which used deceptive ChatGPT conversations to launch ClickFix ruses and compromise targets, but using custom GPTs is a novel approach.

In both attacks, the malicious instructions are hosted on the legitimate ChatGPT.com domain, lending legitimacy to the operation and increasing the chances the victim will follow the instructions.

If executed locally, the provided PowerShell command installs a malicious MSI that launches a legitimate, signed application and a modified DLL loading the malware.

The payload used in this campaign is a remote access trojan (RAT) with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads.

For persistence, the malware creates a new Run key in the Windows Registry and also a scheduled task, both named ‘Canon Configuration Reader.’

The attack chain
Source: Huntress

Huntress says it investigated at least 40 incidents connecting to the Google Sites page but confirmed that only two involved a custom GPT variant.

OpenAI took down the first GPT by September 25. Two days later, on September 27, the researchers found a second GPT linked to the same campaign, which was still active when they published their report.

More recent attacks switched from a Canon-signed host application to a Stardock-signed one and changed how it concealed and delivered the loader, although the payload remained the same.

Old and new attack kits
Source: Huntress

From the multi-stage attack chain, Huntress highlights phase 6, noting that the attackers built a custom encrypted file system to conceal the persistence script and RAT.

“Instead of one encrypted blob, it's a custom archive with its own folder tree, basically a homemade, encrypted zip file,” researchers say.

“It starts with a small header, followed by an index of 1,128 entries (one per file or folder, each recording its parent, its size and a per-file key), and then the file contents, packed back to back.”

Huntress says that most of the infection chain runs in memory or is supported by files that appear benign. This allows defenders to implement detections based on process activity monitoring.

The researchers provide a set of "detection opportunities" that include PowerShell pinging msiexec.exe to silently launch an MSI installer from  the temporary folder.

Additional signs of compromise refer to a signed app starting from an unusual folder under %LOCALAPPDATA%\Programs\, and a matching Run value and scheduled task that reappear if deleted.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat