Huntress

2 items · Attacks 2 · all entities

New A malicious Custom GPT hosted on chatgpt.com walked users into installing a remote access trojan

Huntress researchers Mark O'Halloran and Jonathan Semon describe a Custom GPT named “Plus 5.6,” hosted on chatgpt.com, that sent users to a page on Google Sites presenting as a Cloudflare CAPTCHA check and running a ClickFix lure telling them to paste a command into their terminal, starting an eight-stage chain that sideloaded a remote access trojan through the legitimately signed Canon binary COTFileReadApp.exe and Stardock's DeElevate64.exe. They write that “the Huntress SOC has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance.” Huntress says it “reached out to OpenAI regarding this specific Custom GPT, and it was taken down as of September 25; however, on September 27 Huntress researchers discovered a new Custom GPT linked to the same campaign.” The post assigns no CVE.

Reported by researchersHuntress ↗ ·

Huntress details six-stage macOS stealer delivered through a fake Claude installation guide

Huntress reverse-engineered MacSync, a six-stage macOS infostealer and RAT delivered via a sponsored search ad for Claude installation instructions that redirected to a weaponised Claude.ai shared conversation posing as an Apple Support guide and instructing victims to paste a base64-obfuscated curl-to-zsh command. Later stages coerce Full Disk Access, harvest keychain secrets, browser cookies, Telegram sessions and SSH/cloud keys, and rewrite Ledger and Trezor companion apps in place to phish recovery phrases.

Self-reported, untestedHuntress ↗ ·