Huntress 披露恶意 Custom GPT 借可信域名投放 ClickFix 与 RAT
Huntress披露恶意Custom GPT借可信域名引流ClickFix诈骗
AI 导读
Huntress 研究人员发现,攻击者自 9 月下旬起滥用 ChatGPT 的 Custom GPT 功能,创建名为 Plus 5.6 的 GPT 冒充 ChatGPT 模型,诱导用户点击 Google Sites 链接进入 ClickFix 攻击,最终下载并执行恶意 MSI 并部署 RAT。Huntress SOC 已响应至少 40 起与该 Google Sites 域名相关的事件,其中两起确认经由 Custom GPT 进入;首个 Custom GPT 于 9 月 25 日被下架,但 9 月 27 日又发现同一活动的新 Custom GPT。第二版改用 Stardock 签名程序与 NuGet 包承载加载器,RAT 本体与第一版逐字节相同。Huntress 给出了基于进程行为的检测点,并指出同一服务器上还托管了第三个 MSI。