MediumNewsLLM-specific
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
- Published
- Record updated
Summary
Threat actors are abusing ChatGPT Custom GPTs, which are hosted on the legitimate chatgpt.com site, to point victims to a Google Sites page that uses a fake Cloudflare CAPTCHA to trigger a ClickFix attack. The attack leads to a malicious MSI installer that sideloads a rogue DLL through a Canon-signed binary and ultimately runs a remote access trojan, with at least 40 users infected according to Huntress. The trojan can capture camera, microphone and system audio, run remote desktop sessions, and locate its C2 server via DNS-over-HTTPS.
Related items
- InfoOpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSame vendor · SecurityWeek
- Info‘Pure insanity’: Mathematicians will need years to make sense of OpenAI’s latest dropSame vendor · The Verge (AI)
- InfoOpenAI reports three new incidents of misalignmentSame vendor · CSO Online
- InfoA new feature for my blog, built using my voiceSame vendor · Simon Willison's Weblog
- InfoOpenAI's revenue scare, Delta earnings, what investors think of a Starbucks-Chipotle deal and more in Morning SquawkSame vendor · CNBC Technology