Overview
- Huntress researchers traced a ClickFix campaign that used attacker‑created Custom GPTs on chatgpt.com to steer users to a fake Cloudflare CAPTCHA and ask them to paste a command that launched an eight‑stage infection chain.
- OpenAI removed the first malicious Custom GPT on September 25 and researchers observed a replacement published on September 27, showing attackers quickly retooled delivery hosts and obfuscation after takedowns.
- The chain fetched a malicious MSI that sideloaded a patched DLL through legitimately signed applications (first Canon CaptureOnTouch, later a Stardock binary) and unpacked a byte‑for‑byte identical RAT with remote desktop, audio/video capture, file search, and payload drop capabilities.
- Operators used obfuscation such as decimal‑encoded IPs, loader hiding in NuGet packages, DoH for C2 lookups, and persistence via a Run key plus a scheduled task named “Canon Configuration Reader,” which the implant recreates if removed.
- Huntress urges defenders to block paste‑to‑run tricks, restrict PowerShell and Run dialog use, and hunt for behaviour indicators like PowerShell launching msiexec on GUID‑named MSIs and recurring Run value or scheduled task names rather than relying on domain or signature allowlists.