Security researchers from Huntress have uncovered a new method employed by hackers to misuse ChatGPT’s Custom GPT feature for distributing malware. This campaign leverages trusted ChatGPT-hosted pages to deploy a sophisticated remote access trojan (RAT), posing significant risks to users.
Deceptive Techniques and Attack Strategy
The attackers use a combination of malvertising and fake verification prompts to initiate the attack. They employ obfuscated PowerShell scripts, malicious MSI packages, and DLL sideloading to execute their malicious intent. According to Huntress, the campaign has utilized Google Sites infrastructure in at least 40 incidents, including two traced back to malicious Custom GPTs.
The attack often begins when unsuspecting users search for “chatgpt” on Google and click on a sponsored link that directs them to a deceptive chatgpt.com page. The attackers creatively named their Custom GPT “Plus 5.6,” imitating an official model, although it was identified as a creation by a “community builder.”
Execution and Impact of the Attack
Once users interact with the fake page, they encounter a “Service Availability Notice” that misleadingly alerts them about limited access to the main domain. They are then redirected to a Google Sites page masquerading as a ChatGPT and Cloudflare CAPTCHA verification screen. Here, the ClickFix lure tricks victims into running a PowerShell command.
The command leads to downloading a heavily obfuscated PowerShell script into the system’s temporary directory. This script, after decoding, installs a malicious MSI file, disguises itself as “Advanced Printer Configuration Reader,” and hides from the Programs and Features list.
Technical Analysis and Defensive Measures
In this complex attack chain, the MSI file utilizes DLL sideloading techniques to execute further malicious activities. It loads a Canon-signed executable, which then runs a modified DLL, initiating the RAT’s installation. The malware is capable of remote desktop access, capturing audio and video, and executing additional malicious payloads.
Huntress emphasizes the importance of behavioral detection over reliance on product names, as attackers can easily rotate signed host applications. Key indicators include unexpected PowerShell activity and the execution of signed binaries from atypical paths.
Users are advised to immediately close any pages requesting them to execute shell commands, as legitimate verification processes do not require such actions. The research credits the contributions of several Huntress team members for their investigative efforts.
In conclusion, as cybercriminals continue to innovate in their methods, it is crucial for both users and security professionals to stay informed and vigilant against such sophisticated threats.
