Home RSS TECH Attackers Exploit ChatGPT Custom GPTs to Deliver RATs Through ClickFix Lures

Attackers Exploit ChatGPT Custom GPTs to Deliver RATs Through ClickFix Lures

7
0

Attackers are weaponizing Custom GPTs on ChatGPT, tricking users into clicking malicious links that install remote access trojans (RATs). Discovered by Huntress in late September 2026, this scheme highlights how threat actors exploit trusted AI features and search results to latch onto unsuspecting victims.

—

## How the Attack Unfolds

This campaign’s deceptive setup begins with sponsored Google search results—searches like “chatgpt” yield entries that appear legitimate. Clicking through takes users to two attacker-created Custom GPTs labeled “Plus 5.6.”

Victims using these Custom GPTs see what’s presented as a **Service Availability Notice**, pushing them toward a backup Google Sites domain under the pretense of subscription upgrades or accessibility issues. To create urgency, the message reads: *“We recommend using the backup domain if you need immediate access.”*

Once on the backup domain, the user encounters a fake Cloudflare CAPTCHA. This lures them into executing a seemingly innocent PowerShell command, which facilitates the download of an MSI installer—a file named *ISOSimple.msi*.

—

## Technical Delivery Mechanism

After that command:

– The installer leverages a Canon-signed executable (*COTFileReadApp.exe*) to sideload a modified DLL, *ceiinfolog.dll*.
– That DLL then loads another, unsigned DLL called *rdCore.dll*.
– Hidden inside a .WAV audio file named *Common.Integrator.Preview.wav*, an encrypted loader is embedded.
– Once the loader activates, it bypasses AMSI protections and unhooks *ntdll.dll*.

The RAT payload also checks whether it’s running inside a virtual machine—looking at CPU vendors for VMware, VirtualBox, Hyper-V, QEMU, Xen, or Parallels environments. If no red flags are raised, the trojan unpacks additional components from an encrypted file system file called *monitor.raw*.

—

## Threat Capabilities & Malware Behavior

This RAT delivers an extensive feature set:

– Reports antivirus setup, Microsoft Defender status, and system profile.
– Allows remote desktop access and screen broadcasting.
– Captures video from webcams, microphone inputs, and system audio.
– Interacts with 17 different web browsers, launching the user’s default browser when needed.
– Scans file contents via an inbuilt file manager.
– Executes additional payloads like `.EXE`, `.DLL`, `.MSI`, and script files (PowerShell, VBScript, JavaScript, batch).

For command-and-control (C2) communications, the malware uses DNS-over-HTTPS through Cloudflare, Google, and Quad9—concealing its presence by utilizing well-known, trusted resolvers. The dropper consistently installs a signed binary (*GOMCam2024.exe*) launching Google Chrome with a temporary profile in the %TEMP% folder.

—

## Victims & Broader Campaign Connections

At least 40 users are confirmed to have been infected in these actions.

This isn’t an isolated event. Huntress and other researchers point to multiple related ClickFix-focused operations:

– Phishing sites mimicking OpenAI’s Codex or Anthropic Claude lure victims to fake installation prompts. That click initiates a memory-resident stealer to harvest credentials and crypto wallet data.
– Sites compromised to run EtherHiding and ClearFake scripts, forcing commands that retrieve DLLs—which drop Amatera Stealer and other malicious agents.
– Use of fake CAPTCHA pages via malvertising and phishing, dropping infostealers or forging scripts to persist and reach out to external C2 agents.

Some campaigns target governments, with one cluster (UAT-10820) believed to be aligned with Russian interests.

—

## Lessons for Defense

This campaign emphasizes the evolving tactics used in social engineering and the exploitation of trusted technologies. Users should:

– Be wary of sponsored search results promising app-like interactions or software upgrades.
– Confirm whether a domain in the address bar is official—especially if asking you to run commands or download installers.
– Avoid executing commands unsolicited via emails or links, even if they appear to originate from legitimate sources.
– Regularly update antivirus tools and limit use of macros or PowerShell calls unless trusted and verified.

Security teams must:

– Monitor for new custom AI agent domains posing as official features.
– Inspect DLL sideloading techniques and audio-file carriers of concealed payloads.
– Detect DNS queries using trusted resolvers that could mask C2 traffic.

—

## Closing Thoughts

Threat actors are increasingly integrating AI platforms into their phishing toolkits. By abusing Custom GPTs, Fake CAPTCHA pages, and DLL sideloading techniques, they’ve created multi-layered attacks that mask their tracks and borrow credibility from trusted brands.

In this digital arms race, vigilance—on both the user and organizational sides—remains essential. Always validate before clicking, downloading, or executing anything unusual.

—

This article is AI-generated content. Please verify the information independently before taking any action based on this article.