Malicious ChatGPT GPTs led users to a remote access trojan
Malicious ChatGPT Custom GPTs directed users to a fake CAPTCHA and a command-based malware lure that installed a remote access trojan, according to Huntress. The cybersecurity firm said it responded to at least 40 incidents tied to a Google Sites domain used in the campaign, but confirmed that only two began through a malicious Custom GPT. The broader incident count does not represent 40 infections through the GPT feature. The attackers created a GPT named Plus 5.6 that appeared to offer a legitimate ChatGPT service. Some users reportedly reached it through sponsored Google search results. When opened, the GPT displayed a false notice that the service was limited on the primary domain and directed users to a backup page hosted on Google Sites. That page imitated a Cloudflare CAPTCHA and prompted visitors to copy and run a command, a social-engineering technique known as ClickFix. Huntress said the command launched PowerShell, which retrieved an obfuscated script and silently installed a malicious Windows installer. Running the command themselves could make users less likely to recognize the activity as an attack.