Custom GPTs Abused in ClickFix Campaign to Deliver RAT Malware
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Threat actors are abusing legitimate ChatGPT Custom GPTs to impersonate trusted services and redirect victims to malicious Google Sites. These pages use ClickFix social engineering to convince users to execute PowerShell commands that deploy a multi-stage Remote Access Trojan (RAT). The infection chain also relies on DLL sideloading through signed Canon and Stardock binaries to evade security detection.
Investigation
Huntress researchers identified two separate Custom GPT campaigns connected to the same underlying infrastructure. The investigation uncovered an eight-stage infection chain involving obfuscated PowerShell commands, malicious MSI installers, and steganographic payload delivery through .wav files. Analysts decoded multiple encryption layers and a custom encrypted file system used to conceal the RAT payload and persistence scripts.
Mitigation
Organizations should monitor PowerShell activity involving irm or iex commands that connect to unusual or decimal-formatted IP addresses. Security teams should restrict unsigned DLL execution from application directories and detect unexpected scheduled tasks or registry Run keys created alongside legitimate signed binaries. Users should also be trained to recognize ClickFix lures that instruct them to execute terminal commands.
Response
When malicious activity is detected, responders should terminate the host process, such as COTFileReadApp.exe or DeElevate64.exe, before removing persistence mechanisms. Inspect and delete malicious HKCU Run values and scheduled tasks named Canon Configuration Reader or Stardock DeElevation Tool to prevent reinfection. Perform a comprehensive forensic review for unauthorized network communication, including suspicious DNS-over-HTTPS activity.
Attack Flow
Detections
Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)
Suspicious RunMRU Entry With LOLBin Semantics (via registry_event)
Possible Msiexec Executing Files In Uncommon Directory (via cmdline)
MsiExec Spawned by Shell Process (via cmdline)
Call Suspicious .NET Methods from Powershell (via powershell)
IOCs (HashSha256) to detect: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
IOCs (SourceIP) to detect: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
IOCs (DestinationIP) to detect: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Detection of DLL Sideloading in Canon and Stardock Signed Applications [Windows Sysmon]
Detection of Canon and Stardock Signed Executables Launching from Non-Standard Directories [Windows Process Creation]
Detect PowerShell Download and Execution of Malicious Scripts via ClickFix [Windows Powershell]
Simulation Execution
-
Attack Narrative & Commands: The adversary is utilizing a DLL Sideloading technique, a common method used in recent “ClickFix” campaigns. The goal is to bypass traditional signature-based detection by using a legitimate, signed application (like
COTFileReadApp.exe) to load a malicious DLL. To mimic the specific detection logic provided, the attacker will trigger the execution viamsiexec.exe. This simulates a scenario where a malicious MSI package is run, which then spawns the vulnerable application to execute the sideloaded payload. -
Regression Test Script:
# Simulation of DLL Sideloading via MSIs execution # 1. Create a dummy directory to simulate the application path $workDir = "$env:TEMPCanonSim" New-Item -Path $workDir -ItemType Directory -Force # 2. Create a dummy 'malicious' DLL and the target 'signed' executable # In a real attack, these would be real files; here we create empty files to trigger the process creation rule. New-Item -Path "$workDirceiinfolog.dll" -ItemType File -Force New-Item -Path "$workDirCOTFileReadApp.exe" -ItemType File -Force # 3. Execute the target executable using msiexec.exe as the parent # This matches the 'selection' criteria in the Sigma rule. $targetExe = "$workDirCOTFileReadApp.exe" Start-Process "msiexec.exe" -ArgumentList "/i $targetExe" -Wait -
Cleanup Commands:
# Remove the simulated attack directory and files Remove-Item -Path "$env:TEMPCanonSim" -Recurse -Force