Cybersecurity experts have uncovered a new wave of ClickFix attacks utilizing ChatGPT Custom GPTs to mislead victims into executing harmful software on their devices. These targeted attacks involve impersonating legitimate products to deceive users into downloading malware.
Understanding Custom GPTs in Cyber Attacks
Custom GPTs are tailored versions of ChatGPT, designed with specific instructions and features. Hosted on ChatGPT.com, these tools display custom names and the creator’s profile at the top of their pages. This personalization is being exploited by cybercriminals to enhance their phishing schemes.
In recent incidents reported by cybersecurity firm Huntress, threat actors have programmed Custom GPTs to direct users to a Google Sites link, which subsequently leads to a ClickFix page. Victims on this page are instructed to run PowerShell commands, triggering the download of a malicious MSI file, part of a complex infection chain.
Details of the Malicious Campaign
Huntress reports that the campaign has already compromised at least 40 users, with two incidents directly linked to the fraudulent Custom GPTs. While OpenAI acted to remove one of these GPTs on September 25, another was identified two days later, indicating ongoing efforts by attackers to exploit this method.
The attackers deceived users by naming the Custom GPT “Plus 5.6” and suggesting it was a product from a reputable community builder. The ruse included a fake notification about limited availability, urging users to upgrade or access the service through a backup domain.
Technical Analysis of the Attack
The fraudulent backup domain, hosted on a Google Sites page, included a Cloudflare CAPTCHA check as part of the ClickFix attack strategy. This was aimed at convincing victims to execute PowerShell scripts that installed a malicious application. The initial installer misused a Canon-signed application for DLL sideloading to maintain persistence through a User Run key and a scheduled task disguised as “Canon Configuration Reader.”
Subsequent stages of the attack involved a loader masked as an audio file to avoid detection, executing system checks, and creating a fake loading screen. Ultimately, the attack leveraged a heavily obfuscated audio file containing a custom archive with numerous folders and files, culminating in a RAT capable of executing various payloads.
Although the payload delivered by the second Custom GPT remained the same, the threat actor switched to using a Stardock executable and a patched Stardock DLL for infection, embedding the loader within a Microsoft NuGet package instead of an audio file.
In conclusion, these sophisticated attacks underscore the evolving tactics of cybercriminals and the need for robust security measures to protect against such threats. As hackers continue to innovate their methods, vigilance and timely response by cybersecurity firms and platforms like OpenAI are crucial in mitigating these risks.
