Skip to main content

Malicious Custom GPTs Used for RAT Delivery via ChatGPT Lures

4 min read Runtime Rebel Intel
Primary source: darkreading.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Threat actors use malicious GPTs and legitimate platforms to deliver RATs, compromising users.
  • Users interacting with malicious custom GPTs hosted on OpenAI and Google domains are vulnerable.
  • Educate users on social engineering, verify links, and implement advanced email/web security.

Advertisement

Threat actors are actively leveraging custom-built GPTs on OpenAI’s ChatGPT platform and legitimate Google domains as lures to deliver Remote Access Trojans (RATs). This sophisticated social engineering campaign, identified as similar to “ClickFix-style” attacks, highlights an evolving tactic where adversaries weaponize trusted services and domains to bypass traditional security controls and deceive unsuspecting users, as reported by Dark Reading.

Campaign Overview and Technical Details

The core of this threat involves threat actors creating seemingly legitimate custom GPTs within the ChatGPT environment. These GPTs are designed to appear functional or offer enticing capabilities, thereby piquing user interest. Once a user interacts with a malicious custom GPT, they are guided through a process that ultimately leads to the download and execution of a Remote Access Trojan. This methodology capitalizes on the inherent trust users place in platforms like ChatGPT and the apparent legitimacy of links hosted on domains belonging to OpenAI and Google.

The “ClickFix-style” designation suggests a pattern of attack where legitimate infrastructure is abused to host malicious content or redirect users to phishing sites, often circumventing URL filtering and reputation-based security measures. In this specific campaign, the use of custom GPTs adds a new layer of sophistication. Users might be prompted to click on links or download files under the guise of the custom GPT’s functionality, making it difficult for individuals to discern the malicious intent. The primary objective is the delivery of RATs, which provide attackers with persistent access to compromised systems, enabling data exfiltration, further lateral movement, or installation of additional malware.

Understanding the Threat: Identifying ClickFix-style Social Engineering

The effectiveness of this campaign lies in its ability to exploit trust and familiarity. Users interacting with ChatGPT for various tasks might lower their guard when presented with content or links originating from what appears to be a legitimate OpenAI service or a Google domain. Security professionals investigating how to detect malicious custom GPTs need to focus on behavior rather than just domain reputation. Indicators of compromise might include unusual download prompts from unexpected sources within a chatbot interface, or requests for elevated permissions that seem out of context for the advertised functionality of the GPT. The campaign targets a broad spectrum of users who engage with AI tools, making awareness and critical thinking paramount. The risk extends to individuals and organizations whose employees frequently use public AI services, potentially leading to enterprise network compromise if a corporate device is infected.

Actionable Recommendations and Mitigations for ChatGPT RAT Delivery

Defending against these evolving social engineering tactics requires a multi-layered approach focusing on education, technical controls, and vigilant monitoring.

  • User Education: Conduct regular training sessions for all employees on advanced phishing techniques, particularly those involving social engineering lures on seemingly legitimate platforms. Emphasize the importance of scrutinizing unexpected downloads or requests for sensitive information, even when originating from trusted services.
  • Implement Advanced Email and Web Security: Deploy security solutions capable of dynamic URL analysis and sandbox detonation to detect and block malicious payloads, even if hosted on legitimate domains. These tools can help mitigate ChatGPT RAT delivery by identifying suspicious file behaviors.
  • Endpoint Detection and Response (EDR): Utilize EDR solutions to monitor endpoint activity for signs of RAT installation or execution. Look for unusual process creation, network connections to unknown command-and-control servers, or attempts to modify system configurations.
  • Network Segmentation and Least Privilege: Limit the potential blast radius of a successful compromise through network segmentation. Apply the principle of least privilege, ensuring users and applications only have the necessary permissions to perform their tasks.
  • Review AI Usage Policies: Organizations should establish clear policies regarding the use of public AI services, including custom GPTs. Educate users on the risks associated with third-party tools and advise caution when interacting with unknown or unverified custom GPTs.
  • Monitor for Unusual Downloads: Encourage users to report any suspicious activity or unexpected file downloads encountered while interacting with AI platforms. Implement centralized logging to track application usage and file downloads for anomaly detection.

By combining proactive user education with strong technical controls, organizations can significantly reduce their exposure to threats leveraging sophisticated social engineering techniques through platforms like custom GPTs.

Related: Phishing Targets AI Service Users: Guard Your ChatGPT Accounts, AI Agents Break Sandbox Boundaries in Third-Party Cyber Tests

Advertisement

Advertisement