🛡 MALWARE 🛡

GPTs maliciosos convierten a ChatGPT en señuelo para entregar RATs.

🛡CyberObservatorio
GPTs maliciosos convierten a ChatGPT en señuelo para entregar RATs.
Idioma

GPTs maliciosos convierten a ChatGPT en señuelo para entregar RATs.

Fuente: Dark Reading

**Introducción Contextual**

El reciente auge de los ataques informáticos ha puesto en jaque tanto a usuarios como a organizaciones, especialmente en un contexto donde la inteligencia artificial se ha integrado en múltiples funciones cotidianas. En este sentido, una nueva campaña de ciberataques, denominados ataques ClickFix, ha comenzado a utilizar el dominio legítimo de ChatGPT para infectar a las víctimas con troyanos de acceso remoto (RATs). Este tipo de ataques son particularmente preocupantes, ya que aprovechan la confianza que los usuarios depositan en plataformas de renombre y en la tecnología de inteligencia artificial, lo que aumenta el riesgo de que personas no expertas caigan en la trampa. Esta situación no solo afecta a individuos, sino también a empresas y entidades que utilizan estas herramientas para mejorar su productividad y eficiencia.

**Detalles Técnicos**

Según un informe publicado por Huntress, los atacantes han desarrollado versiones personalizadas de ChatGPT, conocidas como Custom GPTs, que simulan ofrecer las mismas funcionalidades que el producto original de OpenAI. Estas versiones se crean para cumplir diversas funciones, como asistentes de investigación personal o bases de datos de conocimiento para recursos humanos. La técnica utilizada en este ataque se basa en la ingeniería social, donde los atacantes utilizan la infraestructura web confiable de OpenAI para redirigir a las víctimas a un sitio malicioso.

Una vez en el sitio, las víctimas reciben un aviso al estilo ClickFix que intenta engañarlas para que ejecuten un comando de PowerShell. Este comando descarga un archivo MSI que inicia una cadena de infección en múltiples etapas. Huntress identificó al menos dos Custom GPTs que se están utilizando para este propósito. En total, la campaña ha afectado a decenas de usuarios, con el centro de operaciones de seguridad (SOC) de Huntress respondiendo a al menos 40 incidentes relacionados con un dominio específico de Google Sites involucrado en el ataque.

El método ClickFix ha ganado popularidad en los últimos años. Consiste en que la víctima visita un sitio web controlado por el atacante, que a menudo imita un servicio legítimo, como Zoom. En este sitio, se informa a la víctima de que existe un problema técnico que debe ser resuelto copiando y pegando comandos del sistema. La efectividad de esta técnica radica en la confianza que las personas depositan en el software comercial y en su inclinación natural a resolver problemas.

**Impacto y Consecuencias**

La campaña es especialmente engañosa porque los Custom GPTs creados parecen ser instancias legítimas de ChatGPT. Los usuarios acceden a ellos a través del dominio oficial de ChatGPT, y el nombre "Plus 5.6" puede parecer una versión oficial de OpenAI. Una vez que la víctima introduce cualquier solicitud en este Custom GPT, el resultado advierte al usuario que el servicio no está disponible, sugiriendo la posibilidad de actualizar su suscripción o usar un dominio "alternativo", que resulta ser un enlace de Google Sites. Este enlace lleva a una página de aterrizaje falsa de Cloudflare con un CAPTCHA también falso, donde finalmente el usuario se enfrenta a un aviso típico de ClickFix que inicia la cadena de infección.

El comando de PowerShell descarga un archivo MSI que, a su vez, abusa de una aplicación legítima firmada por Canon para cargar DLLs maliciosas. Una de estas DLLs extrae un cargador encriptado oculto dentro de un archivo WAV, lo desencripta y lo ejecuta en memoria. Posteriormente, el cargador recupera el RAT desde un archivo de almacenamiento encriptado separado, descomprimiendo el RAT para su uso. Otra variante del ataque utiliza un portador de cargador diferente y una aplicación firmada distinta, pero la estructura general de la infección parece ser prácticamente idéntica.

El objetivo final de esta infección es desplegar un RAT, que los actores de amenazas suelen usar para obtener una presencia duradera en el entorno de una organización. Aunque las motivaciones exactas de los atacantes no están claras, un RAT puede ser la base para robo de datos, ataques de extorsión, espionaje y más. Según Jonathan Semon, analista principal de operaciones de seguridad en Huntress, de los incidentes investigados, el siguiente paso más común contra las víctimas comprometidas ha sido la instalación de más malware, donde el RAT descarga cargas adicionales destinadas a robar datos del navegador y mapear el endpoint de la víctima.

**Contexto Histórico**

Los ataques ClickFix, como el que se ha identificado recientemente, no son fenómenos nuevos, sino que forman parte de una tendencia creciente en la ingeniería social. Con la digitalización y el uso cada vez más extendido de tecnologías avanzadas, tales como la inteligencia artificial y las plataformas de colaboración, los atacantes han adaptado sus métodos para explotar la confianza y la familiaridad que los usuarios tienen con estas herramientas.

**Recomendaciones**

Para mitigar el riesgo de caer en este tipo de ataques, es fundamental que los usuarios y las organizaciones refuercen sus prácticas de ciberseguridad. La formación en concienciación sobre seguridad debe evolucionar, moviéndose de un enfoque que se centre solamente en verificar el origen de un enlace a uno que examine cuidadosamente lo que se pide al usuario que haga. Es crucial que ningún sitio web, chatbot, página de soporte o herramienta de verificación tenga una razón legítima para solicitar que se peguen comandos en PowerShell o en cualquier terminal, sin importar cuán pulida parezca la presentación.

A medida que la tecnología sigue avanzando, la capacidad de los atacantes para explotar vulnerabilidades en la confianza de los usuarios también lo hará. Por ello, es esencial estar constantemente alerta y educar a los usuarios sobre las amenazas emergentes, así como implementar herramientas de detección y respuesta que puedan ayudar a prevenir compromisos antes de que ocurran.

Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

Source: Dark Reading

A newClickFixattack abuses the real ChatGPT Web domain to infect victims with remote access Trojans (RATs). That's according to Huntress, which this week published its findings about a new campaign that involves malicious Custom GPTs. As the name suggests, these are customized versions ofChatGPTthat users and organizations can create to serve various functions, like personal research assistants, HR knowledge bases for employees, customer-facing product support, and more. According to Huntress' Mark O'Halloran and Jonathan Semon, attackers created Custom GPTs to mimic real product offerings, then leveraged OpenAI's trusted Web infrastructure to direct victims to a malicious site. Victims would then be served a ClickFix-style prompt that attempts to trick them into executing a PowerShell command, which then downloads an MSI file and kicks off the attacker's multistage infection chain. Huntress found two such Custom GPTs being used in this manner. Huntress said the campaignhas affected dozens of users to date; the security firm's security operations center (SOC) "has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance." ClickFixhas become an exceedingly popular social engineering technique in recent years. It typically involves a victim visiting an attacker-controlled website (often mimicking a legitimate service like Zoom), where the victim is told that there is a technical issue and they must copy and paste system commands — the "click" — to "fix" it. The technique works because it exploits trust in commercial software as well as human problem-solving tendencies. This campaign is particularly deceptive because these Custom GPTs are made to look like actual ChatGPT instances. Visitors reach them through the official ChatGPT domain, and to many users, the name, "Plus 5.6," might look like an official OpenAI release. Once the victim types any prompt into this Custom GPT, the output warns the user that the service is unavailable; they can either upgrade their subscription or use the "backup" domain, which is a Google Sites link. That link goes to a fake Cloudflare landing page with afake CAPTCHA, where the user ultimately gets a standard ClickFix prompt to kick off the infection chain. ThePowerShellcommand downloads an MSI file, which abuses alegitimate, Canon-signed application to sideload malicious DLLs. One of those DLLs extracts an encrypted loader hidden inside a WAV file, decrypts it, and executes it in memory. The loader then retrieves the RAT from a separate encrypted storage file. That loader unpacks the RAT. Another variant the researchers discovered uses a different loader carrier and a different signed application, but the general shape of the infection appears to be virtually identical. The infection's ultimate goal is to deploy a RAT, which threat actors often use to gain a durable foothold into an organization's environment. While the exact attacker motivations are unclear, aRATcan form the basis for data theft, extortion-based attacks, espionage, and more. Semon, who is principal security operations analyst at Huntress, tells Dark Reading that of the incidents the company has investigated, the most common next step taken against compromised victims has been the installation of more malware; the RAT pulled down additional payloads intended to steal browser data and map out the victim's endpoint. "Thankfully, our team updated detections fast enough that we got ahead of most of these chains and isolated the machines before the second round of tools landed," he says. Still, the RAT poses significant risks to organizations. "Left alone, though, this RAT is built to do three things: steal data, watch the people using the machine, and serve as a foothold into the rest of the network," Semon says. "It can run hidden remote desktop sessions, turn on the camera and microphone, search every file on the machine, create its own user accounts, and pull in whatever the attacker wants next. On an unmonitored machine, you should assume all of that is on the table." For the technical aspects of the attack, Huntress' blog post includes indicators of compromise, butClickFixattacks areparticularly troublesomebecause they trick the user into initiating the compromise themselves. And for this campaign in particular, perhaps the most dangerous aspect from a social engineering standpoint is that every domain used to gain a foothold in the victim's environment is trusted, namely ChatGPT and Google. Semon says that because the trusted domain stopped being a useful signal, awareness training has to move from "check where it came from" to "check what it's asking you to do." "In some of the incidents we investigated, people searched Google for 'chatgpt,' clicked a sponsored result, and landed on a real chatgpt.com page that passed for a new model, with only a small 'community builder' label as a hint," he says. "The rule that holds up is simple: no website, chatbot, support page, or 'verification tool' has a legitimate reason to tell you to paste a command into PowerShell or any Terminal to verify who you are, no matter how polished it looks." Dark Reading has contacted OpenAI for comment.

GPTs maliciosos convierten a ChatGPT en señuelo para entregar RATs. | Ciberseguridad - NarcoObservatorio