CyberSecurity SEE

Attackers Exploit ChatGPT Custom GPTs to Distribute RAT through Eight-Stage ClickFix Process

Attackers Exploit ChatGPT Custom GPTs to Deploy Remote Access Trojan via ClickFix Attack

Recent research conducted by Huntress has revealed a disturbing trend in cybercrime, whereby threat actors are exploiting ChatGPT’s Custom GPT feature to conduct sophisticated ClickFix attacks. These malicious efforts culminate in the deployment of a fully functional Remote Access Trojan (RAT), posing a significant risk to unsuspecting victims.

The attackers devised a Custom GPT cleverly named “Plus 5.6”, which is designed to mimic a legitimate ChatGPT model. Its presence on the OpenAI-hosted domain chatgpt.com heightens its credibility, making it an alluring target for victims. In numerous cases, individuals stumbled upon this Custom GPT through sponsored Google search results for “chatgpt”. When users interact with the model, they receive disingenuous responses in the form of a “Service Availability Notice”. This false notification guides users to a “backup domain” hosted on Google Sites, further enhancing the ruse.

Upon reaching this deceptive page, victims are confronted with what appears to be a Cloudflare CAPTCHA. The site instructs them to execute a command in their terminal, leading to a sophisticated exploitation process. The PowerShell script, designed to obfuscate its true intent, references a decimal-encoded IP address. This coded approach cleverly bypasses security protocols that typically flag standard dotted IP addresses, enabling the script to download a heavily obfuscated script that stealthily installs a malicious MSI file.

Huntress researchers meticulously documented eight distinct hops between initial ClickFix commands and the final malicious payload. The MSI file initiates a sideload of a compromised Canon logging DLL, which is stealthily executed through a legitimately signed Canon CaptureOnTouch executable. This compromised DLL subsequently loads a helper that extracts a malicious loader concealed within a WAV audio file. This audio file, while containing authentic sound data, has had portions overwritten with encrypted shellcode aimed at executing the malware.

The malicious loader features several advanced evasion techniques, including an Advanced Malware Security Interface (AMSI) bypass, unhooking of the ntdll library, and checks to determine if the program is operating within a virtual machine. The loader proceeds to unpack the RAT from a custom encrypted archive named “monitor.raw”, which contains 806 files, alongside a persistence script written in the malware’s proprietary scripting language.

The RAT itself is equipped with capabilities that pose significant threats, including the ability to conduct remote desktop sessions, capture webcam footage, monitor microphone input, record system audio, and manage files—among other functionalities. Notably, the malware also includes mechanisms for deploying additional payloads in a variety of formats such as EXE, DLL, PowerShell, and ZIP. To obscure its activities, the RAT establishes communication with its command-and-control server via DNS-over-HTTPS Services, utilizing providers like Cloudflare, Google, and Quad9 to avoid detection through local DNS logs.

To maintain persistence, the malware creates a Run key and a scheduled task, both cleverly named “Canon Configuration Reader”. If these are deleted, the malware is capable of re-establishing itself within mere minutes. In one documented incident, Microsoft Defender successfully quarantined the MSI after it had already executed, yet the persistence mechanisms continued to ensure the RAT remained active on the target system.

Huntress’s Security Operations Center (SOC) has responded to at least 40 incidences linked to the Google Sites domain, including two confirmed cases originating from a Custom GPT. Following Huntress’s prompt reporting, OpenAI removed the original malicious Custom GPT on September 25. However, a replacement emerged only two days later, bringing with it a second version of the attack chain. This new variant substitutes in a signed Stardock binary and conceals the loader within a legitimate Microsoft NuGet package. Notably, the RAT remains unchanged in its byte-for-byte structure, indicating a persistent and adaptive threat.

In light of these developments, Huntress advises defenders to prioritize monitoring behavior over file names, given the attackers’ strategy of rotating signed hosts. Key indicators of compromise include the launching of PowerShell with the msiexec command for a GUID-named MSI file in the %TEMP% directory, a legitimate application triggered by msiexec from a fake product folder under %LOCALAPPDATA%\Programs\, and the re-emergence of Run value and scheduled tasks sharing a name after deletion. During malware cleanup, experts recommend terminating the malicious processes before attempting to remove persistent mechanisms.

For a comprehensive technical analysis and detailed indicators of compromise, the full report is available on the Huntress blog: Huntress Blog.

This alarming incident underscores the evolving landscape of cyber threats, demonstrating how familiar and emerging technologies can be manipulated for nefarious purposes. Organizations and individuals must remain vigilant and proactive in protecting themselves against such sophisticated tactics.

Source link

Exit mobile version