Huntress found a campaign abusing ChatGPT Custom GPTs, Google Sites, and ClickFix lures to trick victims into running PowerShell that installs a malicious MSI and deploys DLL sideloading malware. The operation impacted dozens of users, used signed Canon and Stardock binaries to load hidden payloads, and relied on encrypted storage, persistence, and a RAT that could steal data and control infected hosts. #ChatGPT #CustomGPT #Canon #Stardock #GoogleSites
Keypoints
- Attackers abused ChatGPT Custom GPTs to present a convincing lure that redirected victims to a malicious Google Sites page.
- The Google Sites page imitated a Cloudflare CAPTCHA and used a ClickFix technique to persuade users to run a PowerShell command.
- The initial payload downloaded and executed a malicious MSI installer that later abused legitimate signed applications for DLL sideloading.
- The campaign established persistence through an HKCU Run key and a scheduled task, both named to look benign and both able to recreate themselves if removed.
- The infection chain hid code in a .wav file and in an encrypted archive, then decoded a loader and a RAT entirely in memory.
- The RAT provided remote desktop, screen broadcasting, browser launching, file search, payload execution, system reconnaissance, and C2 discovery via DNS-over-HTTPS.
- A second version of the campaign reused the same core malware but swapped the signed host and delivery packaging, showing the operators can rapidly rebrand the attack.
MITRE Techniques
- [T1204.001 ] User Execution: Malicious Link â Victims were lured through a sponsored result and Custom GPT prompts to click through to the malicious chain (âa sponsored result then led them to the Custom GPT pageâ; âthat link then brought them to a Clickfix-style attackâ).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell â The attack used PowerShell to download, stage, and execute the next payload (âThe ClickFix attack kickstarts the rest of the attack and leads to the execution of the following PowerShell commandâ).
- [T1105 ] Ingress Tool Transfer â The script downloaded the MSI from a remote server and retrieved additional components (âdownloads the MSI from the same decimal-IP hostâ).
- [T1218.007 ] System Binary Proxy Execution: Msiexec â The MSI was installed silently using msiexec to blend in with normal system behavior (âinstalls it silently with msiexec /qn /norestartâ).
- [T1574.001 ] Hijack Execution Flow: DLL Search Order Hijacking â The Canon and Stardock executables loaded malicious DLLs from their own folders (âWindows checks the programâs own folder firstâ; âthatâs DLL sideloadingâ).
- [T1574.002 ] Hijack Execution Flow: DLL Side-Loading â A signed Canon/Stardock binary was abused to load patched DLLs that pulled in the next stage (âthe attackers used [the host process]â; âloaded its logger, rdCore.dll came along for the rideâ).
- [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder â Persistence was maintained with an HKCU Run key named Canon Configuration Reader or Stardock DeElevation Tool (âwrites the HKCU Run keyâ; âthe Run valueâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â The malware used a scheduled task for persistence and self-restoration (âa scheduled taskâ; âre-creates it if itâs goneâ).
- [T1027 ] Obfuscated Files or Information â Scripts, strings, and payloads were heavily obfuscated with integer arrays, XOR, and encrypted storage (âone array of 3,036 negative integersâ; âdecoded with a rolling single-byte XORâ).
- [T1140 ] Deobfuscate/Decode Files or Information â Multiple stages decoded hidden scripts and machine code before execution (âreimplemented its decryptionâ; âthe noise turns into x64 machine codeâ).
- [T1027.004 ] Obfuscated Files or Information: Compile After Delivery â A malicious loader was embedded inside a normal-looking .wav file and a NuGet package (âCommon.Integrator.Preview.wav holds up to a quick lookâ; âBuild.dat in a standard zip toolâ).
- [T1497.001 ] Virtualization/Sandbox Evasion: System Checks â The loader and RAT checked for VM-related artifacts and behavior (âAnti-VM checks against CPU vendor strings and a long list of VMware, VirtualBox, Hyper-V, QEMU, Xen and Parallels drivers and servicesâ).
- [T1562.001 ] Impair Defenses: Disable or Modify Tools â The payload attempted to bypass AMSI and unhook ntdll to evade detection (âAn AMSI bypassâ; ântdll unhookingâ).
- [T1056 ] Input Capture â The RAT collected camera, microphone, and system audio, indicating broad user-data capture (âcapture the endpointâs camera input, the microphone and system audioâ).
- [T1018 ] Remote System Discovery â The RAT enumerated host, network, and software details to profile the environment (âInstalled antivirusâ; âopen portsâ; âinstalled softwareâ).
- [T1071.004 ] Application Layer Protocol: DNS â The RAT used DNS-over-HTTPS via major resolvers to locate its Gate/C2 (âuses DNS-over-HTTPS through Cloudflare, Google, and Quad9 serversâ).
- [T1106 ] Native API â The chain relied on Windows-native functionality such as [scriptblock]::Create, msiexec, rundll32, and registry/task APIs (âruns the rebuilt code with [scriptblock]::Createâ; âthrough rundll32 or regsvr32â).
- [T1202 ] Indirect Command Execution â The attack used browser prompts and copy-paste instructions to trick victims into executing commands (âtelling users to copy-and-paste a command into their Terminalâ).
- [T1129 ] Shared Modules â The malicious DLLs were loaded as modules by signed applications to execute code (âthe moment the Canon app loads its logger, rdCore.dll comes along for the rideâ).
Indicators of Compromise
- [URLs] attacker lure and delivery pages â hxxps://chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6, hxxps://sites[.]google[.]com/view/antibot172881
- [URLs] payload delivery and staging â hxxp://1614733393/app/afafa98279c9/ISOSimple[.]msi, hxxp[://]1614733393/s/50d6565cf39e
- [IP addresses] hosting and delivery infrastructure â 96.62.224[.]81 (decimal-encoded as 1614733393), 45.140.205[.]28
- [Files] malicious installers and stagers â ISOSimple.msi, IconEdit2Turb.msi, 6469.ps1, 5689.ps1
- [Files] abused or malicious DLLs â ceiinfolog.dll, rdCore.dll, WPFLocalizeExtension.dll, WMPCL.dll, DeElevator64.dll, I++u.dll
- [Files] embedded payload containers â Common.Integrator.Preview.wav, monitor.raw, Build.dat, execute_engine_disconnect.raw
- [Hashes] installer and component hashes â ISOSimple.msi (6761aad48a3f987238994d92bca97e4b8550e0150607bd67b47b1b6366a371fc), rdCore.dll (b77575413c0f97eaf31e4a44c884c1ecdc0049ec89916ceb0bf3aaaedc0442fe)
- [Hashes] additional sample hashes â COTFileReadApp.exe (278e2f3e2f26c18666b89ef774b4af9ce954e36b2bf54a2392608619245d8c48), monitor.raw (e614b7d5a7a363fb1b355a87e2e8d9e8a05bbbca08f2cee3d606bdb5015ac53e)
- [Persistence names] registry and task names â Canon Configuration Reader, Stardock DeElevation Tool
Read more: https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat