HomeRisk ManagementsAttackers Exploit ChatGPT Feature and ClickFix to Deploy RAT

Attackers Exploit ChatGPT Feature and ClickFix to Deploy RAT

Published on

spot_img

Cybercriminals have developed a sophisticated malware campaign that combines the legitimate features of ChatGPT with a technique known as ClickFix attacks, significantly increasing the risk to unsuspecting victims. This alarming revelation was made by cybersecurity firm Huntress, which uncovered the malicious scheme that has been operational since September.

The campaign exploits the CustomGPT feature of ChatGPT, allowing users to create personalized adaptations of the AI model that adhere to specific instructions and workflows. According to a blog post published by Huntress, the attackers have ingeniously manipulated these CustomGPTs to impersonate legitimate offerings, engaging directly with victims to direct them to various websites that deliver harmful malware.

One particular variant developed by the attackers, named Plus 5.6, has been designed to closely resemble the original ChatGPT interface. As highlighted in Huntress’s findings, victims are funneled to the Plus 5.6 site through sponsored search results that appear when users type “chatgpt” into Google. The deceit begins upon visiting this site, which presents a “Service Availability Notice.” This notice falsely asserts that the model has limited availability on its “primary domain” and encourages users to follow a link to a “backup domain.”

Upon redirection, the backup domain masquerades as a CloudFlare CAPTCHA check, requesting users to paste a command to validate their identity. This ruse constitutes the ClickFix attack, a deceptive technique that capitalizes on social engineering methods to trick victims into executing commands provided by the attackers on their own devices. A critical distinction of this attack is that since the victim is the one initiating the command, it often bypasses traditional security measures that would normally safeguard against unauthorized access.

Huntress emphasizes the trustworthiness of brands being exploited during each step of this attack strategy, invoking well-known names such as ChatGPT, Google, Cloudflare, and even Canon software. Their warning is stark: “No legitimate website will ever ask you to copy and paste a command to prove you’re human.” This important piece of advice serves as a cautionary reminder to internet users about the tactics deployed by cybercriminals.

The link provided through the ClickFix attack ultimately leads the user to a malicious Microsoft Software Installer (MSI). This seemingly innocuous installer is deceptively used to deploy a genuine Canon-signed application that the attackers have cleverly modified to sideload harmful code. The implication of this malicious code is dire; it enables the establishment of a persistent threat on the infected system, granting access to a remote access trojan (RAT) malware.

The RAT is particularly insidious as it allows attackers to monitor the infected system extensively. Not only does it have the capability to capture audio and video through webcams and microphones, but it can also exfiltrate sensitive data to a command-and-control server operated by the perpetrators. In addition, the RAT can deliver further malware and harmful payloads to the compromised machine, making the threat much more severe.

Recent investigations by Huntress have revealed at least 40 confirmed infections tied to this malware campaign. The firm took action by reporting the Plus 5.6 CustomGPT to OpenAI, resulting in the takedown of this particular variant as of September 25. However, despite this setback, researchers have swiftly identified another CustomGPT associated with the ongoing threat, illustrating the resilience and adaptability of these cybercriminals.

In light of these developments, Huntress has issued a stern warning to all users of ChatGPT to remain vigilant and exercise caution. As cyber threats continue to evolve in complexity and sophistication, the importance of awareness and proactive security measures cannot be overstated. The union of trusted technologies with malicious intentions serves as a stark reminder of the ever-present dangers in today’s digital landscape. Users are encouraged to heed the advice from cybersecurity experts and practice safe browsing habits to protect themselves from falling prey to such deceptive attacks.

Source link

Latest articles

Attacker Joins Parks and Recreation Platform to Plant Webshells and Seek Card Data

Security researchers from Huntress have unveiled a sophisticated multi-stage intrusion that targeted three web...

OpenAI Blames Moonshot AI for Coordinated Model Distillation

OpenAI Disrupts Alleged Coordinated Campaign by Moonshot AI to Extract Model Data In a recent...

Cyber Briefing – 2026.09.30 – CyberMaterial

Cybersecurity Landscape: Key Developments and Threats In the realm of cybersecurity, significant incidents and updates...

Accountability for AI Agents Handling Sensitive Data Webinar

George Gerchow: A Leader in Cybersecurity and AI Governance Chief Security Officer, Bedrock Data George Gerchow...

More like this

Attacker Joins Parks and Recreation Platform to Plant Webshells and Seek Card Data

Security researchers from Huntress have unveiled a sophisticated multi-stage intrusion that targeted three web...

OpenAI Blames Moonshot AI for Coordinated Model Distillation

OpenAI Disrupts Alleged Coordinated Campaign by Moonshot AI to Extract Model Data In a recent...

Cyber Briefing – 2026.09.30 – CyberMaterial

Cybersecurity Landscape: Key Developments and Threats In the realm of cybersecurity, significant incidents and updates...