Attackers Leverage ChatGPT Custom GPTs to Distribute a Multi‑Stage Remote Access Trojan
What Happened – Threat actors created malicious “Custom GPT” pages on the legitimate chatgpt.com domain. When a user clicks a sponsored search result, the GPT redirects to a fake Cloudflare CAPTCHA on a Google Sites page, then delivers a ClickFix PowerShell one‑liner that downloads a signed MSI‑based RAT. Huntress observed at least 40 incidents, including two confirmed infections, and reported the abuse to OpenAI, which removed the offending GPTs only to see replacements appear within days.
Why It Matters for Trust & Control Assurance
- Demonstrates how a trusted third‑party AI service can become an un‑vetted attack surface, underscoring the need for continuous vendor‑risk monitoring and evidence of due‑diligence.
- Highlights the importance of logging and correlating web‑proxy, DNS, and endpoint telemetry to detect the multi‑stage delivery chain in real time.
- Shows that control‑assurance programs must include verification of AI‑generated content and associated URLs before they are allowed in the corporate workflow.
Who Is Affected – Enterprises across all sectors that permit employees to use ChatGPT (or similar generative AI tools) for productivity, especially technology‑SaaS firms, professional services, and any organization with open web access.
Recommended Actions
- Enforce web‑filtering rules that block unknown “chatgpt.com/custom‑gpt” URLs and Google Sites pages used for ClickFix lures.
- Require explicit approval and continuous monitoring of any third‑party AI services before they are added to the corporate allow‑list.
- Capture and retain PowerShell command‑line logs, MSI installation events, and scheduled‑task creation alerts for forensic correlation.
- Conduct a rapid review of signed binaries used in the infection chain (Canon, Stardock) against your software‑allow‑list.
- Update security awareness training to include AI‑driven phishing scenarios.
Technical Notes – The campaign uses a sponsored search ad to drive victims to a custom GPT titled “Plus 5.6.” The GPT replies with a “limited availability” message and a link to a backup domain hosted on Google Sites. The backup page presents a fake Cloudflare CAPTCHA, then instructs the user to copy a PowerShell command (using a decimal IP format) into the Windows Run dialog. The command downloads a 27 KB script composed of negative numbers, decodes it in memory, and installs a signed MSI (ISOSimple.msi) that masquerades as a printer‑configuration tool. Persistence is achieved via a Run‑key entry and a scheduled task; the payload loads additional code through DLL sideloading with legitimate signed executables. Source: Security Affairs