Custom versions of ChatGPT promoted in sponsored Google search results are directing users to malicious websites that use ClickFix tactics to install malware, according to reporting by BleepingComputer. Huntress, the managed detection and response company that identified the campaign, said it affected dozens of users.
The attackers created a custom GPT called “Plus 5.6.” It directed users to an alleged backup page on Google Sites, where a fake Cloudflare check instructed them to run a PowerShell command. If run, the command installs a malicious MSI that launches a signed application alongside a modified DLL that loads the malware.
The payload is a remote access trojan (RAT) capable of remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads. It establishes persistence using a Windows Registry Run key and a scheduled task, both named “Canon Configuration Reader.”
Huntress investigated at least 40 incidents involving connections to the Google Sites page, but confirmed that only two involved a custom GPT. OpenAI took down the first GPT by September 25. Researchers found a second one on September 27; it was still active when they published their report. Later attacks used a Stardock-signed application instead of a Canon-signed one, while keeping the same payload.
Huntress also described a custom encrypted archive with an index of 1,128 file and folder entries, used to conceal the persistence script and RAT. The company said much of the infection chain runs in memory or uses files that appear benign, and outlined process activity defenders can monitor.
OpenAI plans to retire custom GPTs on December 11. The source does not specify a year.
Comments
0No comments yet. Be the first to comment.