Users were directed through Google ads to a malicious Custom GPT that sent them to a ClickFix page delivering a remote access trojan.
Attackers are using modified versions of ChatGPT, known as Custom GPTs, to lure users to malicious websites. The GPTs were promoted through sponsored Google search results. The campaign was discovered by cybersecurity company Huntress, which says it identified dozens of affected users.
Custom GPTs are an OpenAI feature that allows users to customize ChatGPT with their own instructions, additional knowledge, and capabilities for specific tasks and publish them for others to use. OpenAI hosts the GPTs itself. The feature is scheduled to be discontinued on December 11.
Fake Cloudflare Check
The malicious GPT was named “Plus 5.6” and directed users to an alleged fallback page hosted on Google Sites. The page displayed a fake Cloudflare verification check that instructed visitors to execute a PowerShell command. This technique is known as ClickFix. Because the instructions were hosted on the legitimate chatgpt.com domain, the process appeared more credible. Previous campaigns had already used shared ChatGPT conversations for ClickFix attacks, but according to Huntress, the use of Custom GPTs is new.
Signed Applications Used as Cover
The PowerShell command installs a malicious MSI package. It launches a legitimate, signed application alongside a tampered DLL that loads the malware. The payload is a remote access trojan that provides remote desktop access, captures audio and camera input, searches files, conducts system reconnaissance, and downloads additional malware.
For persistence, the malware creates a Registry Run key and a scheduled task, both named “Canon Configuration Reader.” In more recent attacks, the threat actors switched from an application signed by Canon to one signed by Stardock.
The attackers hide both the persistence script and the trojan inside a custom-built, encrypted file system.
“Instead of a single encrypted blob, it’s a custom archive with its own folder structure, essentially a self-built, encrypted ZIP file.”
Huntress
It contains an index with 1,128 entries.
Second GPT Still Active
Huntress investigated at least 40 incidents linked to the Google Sites page. In two cases, researchers confirmed that a Custom GPT was involved. OpenAI removed the first GPT by September 25. On September 27, researchers identified a second GPT from the same campaign, which was still active when their report was published.
Signs of Infection
Because much of the infection chain runs in memory or relies on files that appear harmless, Huntress recommends monitoring process activity. Potential indicators include PowerShell launching msiexec.exe to silently install an MSI package from the Temp folder, a signed application launching from an unusual directory under %LOCALAPPDATA%\Programs, and a Registry Run entry and scheduled task that reappear after being deleted.
(Editorial Team)