Cybercriminals are using customized GPT models to power a campaign known as ClickFix, according to researchers from Huntress, a cybersecurity firm. The campaign uses Google ads to lure internet users into clicking on links that direct them to fake security checks. These checks trick users into executing a PowerShell command, which leads to the installation of a remote access Trojan (RAT) on Windows computers. This malware gives attackers extensive control over the infected machine.
The infection vector relies on a GPT named "Plus 5.6," which is promoted through sponsored results on Google and hosted on chatgpt.com. This domain mimics the official site of OpenAI, the company behind the popular GPT technology, in an attempt to inspire trust. The GPT claims that there are difficulties with the main service and directs users to a supposed backup site hosted on Google Sites. Once there, users are presented with a fake anti-bot check that resembles Cloudflare, a well-known security service. This check falsely requires users to run a PowerShell command to access the promised service.
The command retrieves an MSI file that initiates the installation of the malware. This process does not involve exploiting any vulnerabilities in the main ChatGPT service. The installation program deploys several components, including legitimate executables signed by companies like Canon or Stardock. Hackers repurpose these to load a malicious DLL, which is a type of file that can be used to execute harmful code. The Trojan provides attackers with remote desktop control, the ability to search for files, gather information about the system, capture audio and video, or execute additional payloads. To ensure it remains active even after a system restart, the malware creates entries in the Windows Registry and sets up scheduled tasks, named "Canon Configuration Reader" and "Stardock DeElevation Tool" in various forms.
Huntress has linked at least 40 incidents to the page used in this campaign, but only two could be formally linked to a customized GPT. OpenAI had removed the first GPT reported by the researchers on September 25. Two days later, Huntress identified a second one associated with the same operation. Researchers advise that legitimate web verification typically involves checking a box, selecting images, or waiting a few seconds, but certainly not opening PowerShell or the command prompt to copy-paste a command. If a GPT is needed for a specific task, users should use the search function integrated into ChatGPT instead of clicking on a sponsored ad in Google. The GPT Store allows users to view a GPT's name, description, and information about its creator before opening it. Custom GPTs are created by third parties and can legitimately redirect to external sites, but if they ask users to directly interact with the system, the procedure should be stopped immediately. If the command has already been executed, closing the tab will not be enough. Disconnecting the PC from the network, running a full analysis with an up-to-date security solution, and changing sensitive credentials from a healthy device are recommended.
Cybercriminals Exploit Custom GPT Models in New ClickFix Campaign
AI-rewritten from original reportingHow it works
cybercrimemalwaregptgoogle-adsremote-access-trojansecurity



