Ethical Hacking News
Threat actors have been abusing the Custom GPT feature of ChatGPT to deploy a full-featured Remote Access Trojan (RAT). The attack mechanism involves a series of stages, each designed to evade detection and persistence. The use of DLL sideloading and custom encrypted archives makes this attack particularly sophisticated. The detection advice from Huntress is worth taking seriously, as the behaviors carry over between versions, and the attack sequence has stayed consistent across every variant analyzed. This report highlights the importance of staying vigilant in the face of evolving AI-powered malware threats.
Threat actors are using AI-powered malware to deliver sophisticated attacks, including a Custom GPT feature of ChatGPT. The attack mechanism involves a series of stages to evade detection and persistence. The malware uses DLL sideloading and a legitimate Canon application to execute malicious code. The attackers have released two versions of the malware, signed by Canon and Stardock, with changing delivery scripts. The attack carries over between versions and has remained consistent in its sequence.
Threat actors have been utilizing AI-powered malware to deliver sophisticated attacks, leveraging the Custom GPT feature of ChatGPT to deploy a full-featured Remote Access Trojan (RAT). According to recent reports, attackers have abused the Custom GPT feature to trick victims into running PowerShell and installing a malicious payload.
The attack mechanism involves a series of stages, each designed to evade detection and persistence. The initial stage involves a Google Sites page serving a fake Cloudflare CAPTCHA, which leads to a ClickFix attack. The malicious payload is then downloaded and installed using a PowerShell one-liner that downloads and installs a malicious MSI. The MSI file pretends to be an "Advanced Printer Configuration Reader" from a publisher called Softplicity and hides itself from the normal list of installed programs.
The malware then creates a Run key and a scheduled task, allowing the attack to continue. The technical heart of the campaign is DLL sideloading through a legitimately signed Canon application, COTFileReadApp.exe. The attackers replaced the logging library with a modified version that still exports the functions Canon expects but also imports one extra DLL that contains the malicious code.
The malicious code extracts an encrypted loader from a WAV audio file bundled with the installer. The loader is then used to decode a custom encrypted archive that contains a persistence script and the final remote access trojan. The RAT at the end of the chain gives attackers a lot of control, including the ability to run remote desktop sessions, capture the screen, camera, and audio, access data from 17 different browsers, search files across the system, and download or run additional payloads in nine formats.
The attackers have released two versions of the malware, one signed by Canon and the other by Stardock. The delivery script has also changed, removing the Mark-of-the-Web tag from the MSI before launching it, which allows the malware to run without triggering a SmartScreen prompt.
The detection advice from Huntress is worth taking seriously, as the behaviors carry over between versions, and the attack sequence has stayed consistent across every variant analyzed. The report concludes that threat actors continue to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT's Custom GPT feature or through Google Sites for hosting a ClickFix attack.
In recent months, we have seen a rise in AI-powered malware attacks, with attackers using various techniques to deliver sophisticated payloads. The abuse of ChatGPT's Custom GPT feature to deploy a full-featured RAT is a prime example of this trend. As AI technology continues to evolve, it is essential to stay vigilant and adapt our detection strategies to keep pace with the latest threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Abuse-of-AI-Powered-Malware-The-Rise-of-Custom-GPT-Driven-Attacks-ehn.shtml
https://securityaffairs.com/200079/ai/attackers-abuse-chatgpt-custom-gpts-to-deploy-a-full-featured-rat.html
Published: Wed Sep 30 07:34:48 2026 by llama3.2 3B Q4_K_M