ChatGPT Custom GPTs are being abused by threat actors as an entry point for malware campaigns, redirecting users to malicious websites using fake artificial intelligence assistants. A campaign identified by Huntress in which attacker-controlled Custom GPTs were impersonating legitimate ChatGPT offers and directing victims to ClickFix scams has been identified.
A total of 40 incidents associated with the same Google Sites infrastructure were linked to the campaign, and two of these cases have been confirmed to originate from malicious Custom GPTs. OpenAI reported a GPT that had been identified and removed on September 25, however two days later researchers identified another GPT that had been connected to the same campaign.
The attack is initiated by a Custom GPT that appears to be a genuine ChatGPT service.
It has been reported that some victims have reached the malicious GPT by searching for ChatGPT on Google and clicking a sponsored result. While the page itself remained hosted on the legitimate ChatGPT domain, the GPT was titled Plus 5.6, giving the appearance that it was an official model.
A false message claiming that the primary domain was restricted to a limited number of users was displayed when the GPT was opened.
After that, the website directed users to a fake backup website hosted on Google Sites, where a false Cloudflare CAPTCHA was displayed and a technique known as ClickFix was utilized to entice the victim into manually executing a command.
PowerShell is launched by the command to retrieve an obfuscated script, which is temporarily saved before executing. After a silent download of a malicious MSI package named ISOSimple.msi, the script silently installs it. During the subsequent attack chain, the installer appears to be a legitimate Canon-signed application that is used to install an “Advanced Printer Configuration Reader”.
Even when security software detected part of the payload, the infection was designed to remain active. One incident involved Microsoft Defender quarantining ISOSimple.msi as Trojan:Script/Wacatac.H!ml, because it had already set up a Run key and a scheduled task called “Canon Configuration Reader.” These keys and tasks allowed the malware to continue running on the computer.
DLL sideloading is the next stage. With the MSI, the legitimate Canon COTFileReadApp.exe is installed, which has a valid digital signature, making the malicious package appear less suspicious. Attackers inserted a modified logging library alongside the executable, causing the legitimate Canon application to load malicious code through Windows' DLL search process as a result.
The sideloaded code then extracts the next payload from a .wav file included in the installer Even though the file contains authentic audio data at the beginning and a valid WAV header, there are later sections that contain encrypted data that is decoded in memory.
To avoid simple file-based detection, the loader retrieves an encrypted archive containing the malware and its persistence components and eventually eliminates straightforward file-based detection.
There are 315 folders and 806 files contained within the archive, known as monitor.raw, which has a custom encrypted file structure. It contains a persistence script that continuously checks the registry for the malware's run entry and scheduled task, and recreates them if they are removed.
In both instances, the infection can be re-executed by launching the Canon executable under the name "Canon Configuration Reader" by launching the Canon executable.
An advanced Remote Access Trojan is attached to the final payload, which can provide access to the computer's desktop and screen, capture input from the camera, microphone, and audio system, and search for files on the computer.
Additionally, the program collects information regarding security software installed, Windows configuration, network adapters, open ports, software installed and hardware installed.
Command-and-control communication is carried out through DNS-over-HTTPS via services such as Cloudflare, Google, and Quad9, allowing its network traffic to blend in with legitimate encrypted web traffic.
In addition to downloading and executing additional EXE, DLL, MSI, PowerShell, and script-based payloads, attackers can extend activity beyond the initial compromise by downloading additional payloads.
After removing the first Custom GPT from the campaign, Hunters discovered a second version. In addition to keeping the underlying RAT unchanged, the attackers replaced the Canon-based execution chain with a modified DLL and signed Stardock executables.
In addition, the loader was moved from the WAV file into a Microsoft NuGet package, demonstrating that the delivery components can be changed without replacing the core malware.
A second variant included additional measures to make detection more difficult, including freshly obfuscated download scripts and the removal of Windows Mark-of-the-Web tags before the MSI was executed.
Nonetheless, the main behavior remained the same: MSI installation resulted from PowerShell activity, malicious code was loaded from a legitimate signed application, and persistent registry and scheduled task access was maintained.
Therefore, security researchers advise that detection should be focused on behavior connecting these stages rather than relying solely on specific filenames or trusted software brands. It is possible to detect this type of attack by suspicious PowerShell activity followed by Msiexec, signed applications running from unusual locations, unexpected DLL loading, and newly created Run keys and scheduled tasks.
