ClickFix RAT Disguised as Custom ChatGPT Bot Strikes

Custom ChatGPT bot interface mimicking a service error to trigger the ClickFix RAT infection chain
Any interaction with this Custom GPT results in the message above

The most compelling element of this novel cyberattack resides not upon a disparate phishing domain, but directly within the authentic ChatGPT interface. Huntress unveiled a sophisticated campaign wherein adversaries engineered custom GPTs, masquerading them as nascent platform functionalities to manipulate users into manually executing malicious commands within their Windows environments.

One such deceptive bot, designated “Plus 5.6,” operated seamlessly within chatgpt.com. In numerous documented incidents, victims inadvertently accessed this malicious entity by clicking fraudulent Google advertisements targeting the keyword “chatgpt”. Any communication directed to the bot precipitated an identical, pre-programmed response lamenting service disruptions and insisting the user navigate to a designated fallback page, conveniently hosted on Google Sites.

The Evolution of the ClickFix Maneuver

This fallback page meticulously simulated a standard Cloudflare security verification process, thereby initiating the notorious ClickFix mechanism. The interface persuasively instructed the victim to copy a specific command and manually execute it within the Windows Run dialog. Consequently, PowerShell downloaded a heavily obfuscated script that silently deployed a malicious MSI package, triggering a complex, multi-stage infection sequence.

This particular infection chain proved remarkably more intricate than standard ClickFix deployments. Huntress analysts meticulously delineated eight distinct stages. The initial iteration cunningly abused a legitimately signed Canon CaptureOnTouch application, exploiting a DLL sideloading vulnerability wherein the benign executable unwittingly loads a malicious, substitute library from its resident directory. The subsequent loader surreptitiously concealed itself within a genuine WAV file, intricately woven among standard audio data.

A Sophisticated Payload Delivery System

Following decryption, the loader aggressively bypassed the Antimalware Scan Interface (AMSI), systematically attempted to unhook Endpoint Detection and Response (EDR) telemetry, rigorously probed for virtual machine environments, and executed its payload directly within volatile memory. Another critical component, designated “monitor.raw,” harbored an autonomous, encrypted file system encompassing 1,128 distinct entries. This repository concealed a robust persistence script and the ultimate Remote Access Trojan (RAT).

This sophisticated RAT bestowed the operators with comprehensive remote desktop capabilities, live screen broadcasting, and unfettered access to the victim’s camera, microphone, system audio, and local file system. Furthermore, the malware possessed the capability to launch supplementary executables, DLLs, MSIs, and scripts. It actively audited installed security software, network configurations, and underlying hardware. To locate its command and control infrastructure, the implant utilized DNS-over-HTTPS queries routed through public resolvers.

Rapid Adaptation and Persistent Threats

OpenAI swiftly eradicated the initial malicious GPT on September 25, responding promptly to notification from Huntress. However, by September 27, security specialists had already identified a fully operational replacement. In this secondary iteration, the adversaries discarded the Canon application in favor of a signed Stardock component and seamlessly concealed the loader within an authentic Microsoft NuGet package. Notably, the core RAT binary remained identical, demonstrating the operators’ capacity to rapidly reconfigure the attack’s external facade.

Huntress definitively associated no fewer than 40 distinct security incidents with the specific Google Sites domain utilized. However, they directly traced only two confirmed infections to the initial interaction with the custom GPT. This campaign perpetuates a distressing trend wherein a universally trusted domain constitutes a critical component of the lure. Crucially, the attackers required no underlying vulnerability within ChatGPT; they simply weaponized the legitimate Custom GPT functionality and exploited the inherent trust users place in ubiquitous technological brands.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply