Custom ChatGPTs Used in ClickFix Campaign to Deploy RAT Malware

OpenAI's feature abused to lure users into running malicious PowerShell commands

By LineZotpaper
Published
Read Time2 min
Threat actors have been abusing OpenAI's custom ChatGPT feature to push 'ClickFix' attacks that deliver remote access trojans (RATs) to unsuspecting users, security researchers at Huntress have discovered. The malicious campaign uses custom GPTs hosted on the legitimate ChatGPT domain to direct victims to fake Cloudflare verification pages that trick them into running PowerShell commands that install malware.

Huntress researchers identified the campaign after investigating at least 40 incidents linked to a Google Sites page used in the attack. The threat actor created a custom GPT named 'Plus 5.6' that directed users to an alleged backup site hosted on Google Sites. The site displayed a fake Cloudflare check and instructed visitors to run a PowerShell command, which deployed a multi-stage infection chain.

The PowerShell command installs a malicious MSI that launches a legitimate, signed application and a modified DLL that loads the remote access trojan. The RAT provides capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads. For persistence, the malware creates a Run key and a scheduled task, both named 'Canon Configuration Reader', though more recent attacks switched to a Stardock-signed application.

OpenAI removed the first malicious GPT by September 25, but a second variant was found active on September 27. The company plans to retire the custom GPTs feature entirely on December 11, which may limit future abuse.

Huntress noted the attackers built a custom encrypted file system to conceal the persistence script and RAT. "Instead of one encrypted blob, it's a custom archive with its own folder tree, basically a homemade, encrypted zip file," the researchers said.

The attack chain is similar to past ClickFix campaigns that used deceptive ChatGPT conversations, but this is the first known abuse of the custom GPT feature.

§

Analysis

Why This Matters

  • Users may trust instructions from ChatGPT, making them vulnerable to social engineering attacks
  • The abuse of a legitimate AI feature highlights a new vector for malware distribution
  • OpenAI's planned retirement of custom GPTs may reduce such risks, but attackers could shift to other platforms

Background

OpenAI introduced custom GPTs in late 2023, allowing users to create tailored versions of ChatGPT for specific tasks by combining custom instructions, knowledge, and skills. These GPTs are hosted on the ChatGPT.com domain and can be published for others to use. ClickFix attacks are a social engineering technique that tricks users into running malicious commands by presenting fake security checks, such as a bogus Cloudflare verification page.

Key Perspectives

Security researchers (Huntress): The campaign affected dozens of users and represents a novel evolution of ClickFix tactics, leveraging the trust associated with ChatGPT's domain. They emphasize the multi-stage nature of the attack and the custom encrypted file system used to evade detection. OpenAI (platform provider): The company has taken down identified malicious GPTs and plans to retire the custom GPTs feature in December. However, the platform's openness to third-party GPTs creates risk of abuse before the feature ends. Critics/skeptics: The reliance on a single social engineering technique (fake Cloudflare check) may limit the campaign's effectiveness. The retirement of custom GPTs does not address similar abuse risks in other AI platforms that allow user-created content.

What to Watch

  • Whether OpenAI accelerates the retirement of custom GPTs or adds interim security measures
  • If the threat actors shift to abusing other AI platforms' custom features
  • Additional variants of the attack using different signed applications or payloads

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.