Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix | Huntress

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix | Huntress
Huntress found a campaign abusing ChatGPT Custom GPTs, Google Sites, and ClickFix lures to trick victims into running PowerShell that installs a malicious MSI and deploys DLL sideloading malware. The operation impacted dozens of users, used signed Canon and Stardock binaries to load hidden payloads, and relied on encrypted storage, persistence, and a RAT that could steal data and control infected hosts. #ChatGPT #CustomGPT #Canon #Stardock #GoogleSites

Keypoints

  • Attackers abused ChatGPT Custom GPTs to present a convincing lure that redirected victims to a malicious Google Sites page.
  • The Google Sites page imitated a Cloudflare CAPTCHA and used a ClickFix technique to persuade users to run a PowerShell command.
  • The initial payload downloaded and executed a malicious MSI installer that later abused legitimate signed applications for DLL sideloading.
  • The campaign established persistence through an HKCU Run key and a scheduled task, both named to look benign and both able to recreate themselves if removed.
  • The infection chain hid code in a .wav file and in an encrypted archive, then decoded a loader and a RAT entirely in memory.
  • The RAT provided remote desktop, screen broadcasting, browser launching, file search, payload execution, system reconnaissance, and C2 discovery via DNS-over-HTTPS.
  • A second version of the campaign reused the same core malware but swapped the signed host and delivery packaging, showing the operators can rapidly rebrand the attack.

MITRE Techniques

  • [T1204.001 ] User Execution: Malicious Link – Victims were lured through a sponsored result and Custom GPT prompts to click through to the malicious chain (‘a sponsored result then led them to the Custom GPT page’; ‘that link then brought them to a Clickfix-style attack’).
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – The attack used PowerShell to download, stage, and execute the next payload (‘The ClickFix attack kickstarts the rest of the attack and leads to the execution of the following PowerShell command’).
  • [T1105 ] Ingress Tool Transfer – The script downloaded the MSI from a remote server and retrieved additional components (‘downloads the MSI from the same decimal-IP host’).
  • [T1218.007 ] System Binary Proxy Execution: Msiexec – The MSI was installed silently using msiexec to blend in with normal system behavior (‘installs it silently with msiexec /qn /norestart’).
  • [T1574.001 ] Hijack Execution Flow: DLL Search Order Hijacking – The Canon and Stardock executables loaded malicious DLLs from their own folders (‘Windows checks the program’s own folder first’; ‘that’s DLL sideloading’).
  • [T1574.002 ] Hijack Execution Flow: DLL Side-Loading – A signed Canon/Stardock binary was abused to load patched DLLs that pulled in the next stage (‘the attackers used [the host process]’; ‘loaded its logger, rdCore.dll came along for the ride’).
  • [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – Persistence was maintained with an HKCU Run key named Canon Configuration Reader or Stardock DeElevation Tool (‘writes the HKCU Run key’; ‘the Run value’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – The malware used a scheduled task for persistence and self-restoration (‘a scheduled task’; ‘re-creates it if it’s gone’).
  • [T1027 ] Obfuscated Files or Information – Scripts, strings, and payloads were heavily obfuscated with integer arrays, XOR, and encrypted storage (‘one array of 3,036 negative integers’; ‘decoded with a rolling single-byte XOR’).
  • [T1140 ] Deobfuscate/Decode Files or Information – Multiple stages decoded hidden scripts and machine code before execution (‘reimplemented its decryption’; ‘the noise turns into x64 machine code’).
  • [T1027.004 ] Obfuscated Files or Information: Compile After Delivery – A malicious loader was embedded inside a normal-looking .wav file and a NuGet package (‘Common.Integrator.Preview.wav holds up to a quick look’; ‘Build.dat in a standard zip tool’).
  • [T1497.001 ] Virtualization/Sandbox Evasion: System Checks – The loader and RAT checked for VM-related artifacts and behavior (‘Anti-VM checks against CPU vendor strings and a long list of VMware, VirtualBox, Hyper-V, QEMU, Xen and Parallels drivers and services’).
  • [T1562.001 ] Impair Defenses: Disable or Modify Tools – The payload attempted to bypass AMSI and unhook ntdll to evade detection (‘An AMSI bypass’; ‘ntdll unhooking’).
  • [T1056 ] Input Capture – The RAT collected camera, microphone, and system audio, indicating broad user-data capture (‘capture the endpoint’s camera input, the microphone and system audio’).
  • [T1018 ] Remote System Discovery – The RAT enumerated host, network, and software details to profile the environment (‘Installed antivirus’; ‘open ports’; ‘installed software’).
  • [T1071.004 ] Application Layer Protocol: DNS – The RAT used DNS-over-HTTPS via major resolvers to locate its Gate/C2 (‘uses DNS-over-HTTPS through Cloudflare, Google, and Quad9 servers’).
  • [T1106 ] Native API – The chain relied on Windows-native functionality such as [scriptblock]::Create, msiexec, rundll32, and registry/task APIs (‘runs the rebuilt code with [scriptblock]::Create’; ‘through rundll32 or regsvr32’).
  • [T1202 ] Indirect Command Execution – The attack used browser prompts and copy-paste instructions to trick victims into executing commands (‘telling users to copy-and-paste a command into their Terminal’).
  • [T1129 ] Shared Modules – The malicious DLLs were loaded as modules by signed applications to execute code (‘the moment the Canon app loads its logger, rdCore.dll comes along for the ride’).

Indicators of Compromise

  • [URLs] attacker lure and delivery pages – hxxps://chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6, hxxps://sites[.]google[.]com/view/antibot172881
  • [URLs] payload delivery and staging – hxxp://1614733393/app/afafa98279c9/ISOSimple[.]msi, hxxp[://]1614733393/s/50d6565cf39e
  • [IP addresses] hosting and delivery infrastructure – 96.62.224[.]81 (decimal-encoded as 1614733393), 45.140.205[.]28
  • [Files] malicious installers and stagers – ISOSimple.msi, IconEdit2Turb.msi, 6469.ps1, 5689.ps1
  • [Files] abused or malicious DLLs – ceiinfolog.dll, rdCore.dll, WPFLocalizeExtension.dll, WMPCL.dll, DeElevator64.dll, I++u.dll
  • [Files] embedded payload containers – Common.Integrator.Preview.wav, monitor.raw, Build.dat, execute_engine_disconnect.raw
  • [Hashes] installer and component hashes – ISOSimple.msi (6761aad48a3f987238994d92bca97e4b8550e0150607bd67b47b1b6366a371fc), rdCore.dll (b77575413c0f97eaf31e4a44c884c1ecdc0049ec89916ceb0bf3aaaedc0442fe)
  • [Hashes] additional sample hashes – COTFileReadApp.exe (278e2f3e2f26c18666b89ef774b4af9ce954e36b2bf54a2392608619245d8c48), monitor.raw (e614b7d5a7a363fb1b355a87e2e8d9e8a05bbbca08f2cee3d606bdb5015ac53e)
  • [Persistence names] registry and task names – Canon Configuration Reader, Stardock DeElevation Tool


Read more: https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat