A novel attack campaign is leveraging custom variants of OpenAI's ChatGPT, promoted through sponsored Google search results, to direct users to malicious websites. These sites employ "ClickFix" social engineering tactics to deliver remote access trojan (RAT) malware. The campaign was identified by Huntress, a managed detection and response firm, which noted that dozens of users have been affected.
The threat actors are exploiting a legitimate feature within OpenAI's platform that allows users to create customized versions of ChatGPT for specific tasks, incorporating tailored instructions, knowledge, and skills. OpenAI hosts these custom GPTs, which can be published for public use. OpenAI has announced plans to discontinue custom GPTs on December 11.
Huntress researchers observed the malicious GPT model, named "Plus 5.6," configured to redirect users to an alleged backup site hosted on Google Sites. This page then displays a fabricated Cloudflare security check and instructs visitors to execute a PowerShell command. If run, this command initiates the infection chain.
The PowerShell command installs a malicious MSI package. This package then launches a legitimate, signed application, which in turn loads a modified DLL containing the malware. The payload is a RAT capable of remote desktop access, audio and camera capture, file searching, host reconnaissance, and deploying additional payloads. For persistence, the malware creates a new Run key in the Windows Registry and a scheduled task, both named "Canon Configuration Reader."
Huntress investigated at least 40 incidents involving connections to the malicious Google Sites page. While only two were confirmed to involve a custom GPT variant, the first malicious GPT was taken down by OpenAI on September 25. However, a second GPT linked to the same campaign was discovered by researchers on September 27 and remained active at the time of their report.
More recent iterations of the attack have shifted from using a Canon-signed host application to a Stardock-signed one. The method for concealing and delivering the loader has also changed, though the core RAT payload remains consistent.
A notable aspect of the multi-stage attack chain, highlighted by Huntress, is the attackers' creation of a custom encrypted file system to hide the persistence script and the RAT. This custom archive functions like a homemade, encrypted zip file, complete with its own folder structure. It begins with a small header, followed by an index of 1,128 entries (one for each file or folder, detailing its parent, size, and a per-file key), and then the packed file contents.
Huntress noted that much of the infection chain operates in memory or relies on files that appear benign, suggesting that defenders can implement detections based on process activity monitoring. The researchers provided several "detection opportunities," including PowerShell silently launching an MSI installer from a temporary folder, a signed application starting from an unusual location under `%LOCALAPPDATA%\Programs\`, and the reappearance of a matching Run value and scheduled task if deleted.






