BlackTree Security · Infrastructure · Automation · AI

A Real ChatGPT Page Led Users Into a Fake Verification Trap

An attacker-built Custom GPT called “Plus 5.6” appeared at a real chatgpt.com address and presented a false service notice. It pointed users to a Google Sites “backup”, where a fake Cloudflare check told them to run PowerShell. Huntress confirmed two infections that began at a Custom GPT. Its security operations centre handled at least 40 incidents tied to that Sites domain; it did not establish a GPT entry point for the rest.

In some cases, a sponsored search result led to the GPT. Huntress traced the copied command to a malicious MSI, a signed Canon application loading a modified DLL, persistence and a remote access trojan. A later version used a signed Stardock host. Huntress says the first GPT was removed by 25 September; a linked replacement was active when its 28 September report appeared. That is a dated observation, not a claim of current availability or a platform breach.

Does a real ChatGPT address make the instruction safe?

No. OpenAI’s documentation describes Custom GPTs as configurable with builder-supplied instructions. Huntress says this page identified its author as a community builder while borrowing a model-like name. The hostname showed where the page lived, not whether its “service availability” message was official.

BlackTree analysis: The decisive point was the handoff from a hosted conversation to an unrelated “backup” site, then from a web check to Windows Terminal. Each change of context needs its own trust decision. A user can leave that flow and reach the service through a saved, independently obtained route. A CAPTCHA or service notice that asks for a pasted shell command is an instruction to execute code, not a verification step. Checking the builder label and the destination matters more than recognising the first hostname.

What should a SOC examine if the command was run?

Huntress describes one case in which an antivirus product quarantined the MSI after it had run, while persistence remained. Closing the browser or seeing a quarantine alert therefore does not settle the endpoint’s state. BlackTree analysis: preserve the evidence and triage in this order:

  • Reconstruct the process chain from PowerShell to msiexec and a changing-name MSI in the temporary directory. This distinguishes an executed lure from a page visit.
  • Check whether a signed Canon or Stardock program ran from an unexpected user-writable folder with an adjacent modified DLL. A valid signature on the host program does not validate its neighbours.
  • Correlate the user’s Run key and scheduled tasks, including Huntress’s observed Canon Configuration Reader and Stardock DeElevation Tool names, with execution and outbound activity. Isolate a matching host while retaining its timeline.

These are triage pivots, not a claim that every variant leaves identical files. Huntress provides detailed indicators in its report; use them alongside process and persistence behaviour, not as a reason to block all Canon or Stardock software. For wider scoping, separate people who viewed the GPT, people who reached the Google Sites page and endpoints that actually ran the command. The shared Sites domain alone cannot prove each visitor arrived through a GPT.

BlackTree’s separate TerminalFix report followed a different payload and infrastructure. The common response principle is to identify where a routine-looking page asks a person to perform the attacker’s execution step.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *