{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Attackers are abusing high-trust domains like ChatGPT to bypass web filters. A negative result confirms that social engineering via Custom GPTs has not successfully breached the estate."
      },
      "name": "ChatGPT Custom GPT ClickFix Lure and MSI Installer",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1059.001",
        "attack.t1574.002",
        "attack.t1547.001",
        "attack.t1053.005",
        "defense evasion",
        "execution",
        "initial access",
        "persistence"
      ],
      "series": {
        "slug": "attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix",
        "index": 1,
        "title": "Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix",
        "total": 2
      },
      "related": [
        {
          "hunt": "canon-reader-dll-sideloading",
          "reason": "This hunt focuses on initial access; the subsequent sideloading and RAT execution require different hypotheses.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "The hunt evaluates cheap decimal-IP leads before running expensive temporal DNS and file-prevalence queries, providing a level of context that a single static rule would miss.",
      "coverage": [
        {
          "stage": "initial-access-custom-gpt-lure",
          "steps": [
            "dns-lure-redirection"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-clickfix-terminal-paste",
          "steps": [
            "powershell-decimal-ip-lead"
          ],
          "status": "covered"
        },
        {
          "stage": "execution-msi-deployment",
          "steps": [
            "msi-file-creation"
          ],
          "status": "covered"
        },
        {
          "stage": "persistence-canon-reader",
          "reason": "Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "defense-evasion-dll-sideloading",
          "reason": "Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "collection-stego-payload-extraction",
          "reason": "Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Custom GPT Redirect",
            "slug": "initial-access-custom-gpt-lure",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "chatgpt.com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6",
              "chatgpt.com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6",
              "sites.google.com/view/antibot172881"
            ]
          },
          {
            "name": "ClickFix PowerShell Execution",
            "slug": "execution-clickfix-terminal-paste",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "PowerShell.exe -ExecutionPolicy Bypass \"irm 1614733393/12",
              "1614733393/12",
              "1777.ps1",
              "6469.ps1",
              "96.62.224.81"
            ]
          },
          {
            "name": "Malicious MSI Installation",
            "slug": "execution-msi-deployment",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "ISOSimple.msi",
              "msiexec /qn /norestart",
              "%TEMP%\\*_ISOSimple.msi"
            ]
          },
          {
            "name": "Dual-Mechanism Persistence",
            "slug": "persistence-canon-reader",
            "tactic": "persistence",
            "techniques": [
              "T1547.001",
              "T1053.005"
            ],
            "observables": [
              "Canon Configuration Reader",
              "Software\\Microsoft\\Windows\\CurrentVersion\\Run",
              "C:\\Windows\\System32\\Tasks"
            ]
          },
          {
            "name": "Canon App DLL Sideloading",
            "slug": "defense-evasion-dll-sideloading",
            "tactic": "defense-evasion",
            "techniques": [
              "T1574.002"
            ],
            "observables": [
              "COTFileReadApp.exe",
              "ceiinfolog.dll",
              "rdCore.dll",
              "WPFLocalizeExtension.dll",
              "WMPCL.dll",
              "%LOCALAPPDATA%\\Programs\\Advanced Printer Configuration Reader\\"
            ]
          },
          {
            "name": "Steganographic Loader Unpacking",
            "slug": "collection-stego-payload-extraction",
            "tactic": "execution",
            "techniques": [
              "T1059.001"
            ],
            "observables": [
              "Common.Integrator.Preview.wav",
              "monitor.raw"
            ]
          }
        ],
        "summary": "Attackers leverage malicious ChatGPT Custom GPTs to direct victims to a ClickFix lure on Google Sites, inducing them to execute a PowerShell command that downloads a multi-stage loader. The campaign culminates in the installation of a remote access trojan (RAT) through a Canon-signed application manipulated via DLL sideloading and persistent scheduled tasks."
      },
      "severity": "high",
      "rationale": "Start with all enrolled Windows endpoints. The primary lead is the PowerShell decimal host pattern (e.g., 1614733393).",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.",
      "parameters": {
        "decimal_ip": {
          "from": {
            "ref": "huntress",
            "kind": "article",
            "observed": "2026-09-28"
          },
          "type": "string",
          "default": "1614733393",
          "description": "Decimal-encoded IP address observed in ClickFix PowerShell commands."
        },
        "scope_hosts": {
          "from": {
            "ref": "analyst-defined",
            "kind": "manual",
            "observed": "2026-09-28"
          },
          "type": "list[host]",
          "default": [],
          "description": "Optional list of hostnames to narrow the search."
        },
        "lure_domains": {
          "from": {
            "ref": "huntress",
            "kind": "article",
            "observed": "2026-09-28"
          },
          "type": "list[domain]",
          "default": [
            "chatgpt.com",
            "sites.google.com"
          ],
          "description": "Domains hosting the Custom GPT lure and the ClickFix redirect page."
        },
        "lookback_days": {
          "from": {
            "ref": "default-retention",
            "kind": "manual",
            "observed": "2026-09-28"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat",
          "name": "Huntress \u2014 Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix"
        }
      ],
      "blind_spots": [
        {
          "id": "visibility-gap",
          "risk": "DNS only shows the domain; without proxy logs, we cannot distinguish a legitimate ChatGPT visit from the malicious redirect path.",
          "stage": "initial-access-custom-gpt-lure",
          "question": "whether the user visited the specific Custom GPT path",
          "requires": "hb_http_activity with full url_path"
        },
        {
          "id": "script-obfuscation",
          "risk": "The script uses nested loops and integer shifting; the analyst must manually decode it if the script block is not captured.",
          "stage": "execution-clickfix-terminal-paste",
          "question": "what the second-layer PowerShell script performs",
          "requires": "hb_script_activity"
        }
      ]
    },
    "name": "ChatGPT Custom GPT ClickFix Lure and MSI Installer",
    "description": "This hunt identifies a multi-stage infection chain beginning with a social engineering lure on the legitimate ChatGPT domain. Attackers use a Service Availability Notice to redirect victims to a Google Sites page. This page delivers a ClickFix command that executes PowerShell to fetch a script from a decimal-encoded IP address, which then installs a malicious MSI. The hunt opens with a scoping step for Windows systems, identifies PowerShell leads reaching decimal host strings, and then gates on an agent's assessment before performing a fan-out of network and file queries to confirm the infection."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix",
          "index": 1,
          "title": "Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-custom-gpt-lure",
            "steps": [
              "dns-lure-redirection"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-clickfix-terminal-paste",
            "steps": [
              "powershell-decimal-ip-lead"
            ],
            "status": "covered"
          },
          {
            "stage": "execution-msi-deployment",
            "steps": [
              "msi-file-creation"
            ],
            "status": "covered"
          },
          {
            "stage": "persistence-canon-reader",
            "reason": "Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "defense-evasion-dll-sideloading",
            "reason": "Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "collection-stego-payload-extraction",
            "reason": "Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.",
        "blind_spots": [
          {
            "id": "visibility-gap",
            "risk": "DNS only shows the domain; without proxy logs, we cannot distinguish a legitimate ChatGPT visit from the malicious redirect path.",
            "stage": "initial-access-custom-gpt-lure",
            "question": "whether the user visited the specific Custom GPT path",
            "requires": "hb_http_activity with full url_path"
          },
          {
            "id": "script-obfuscation",
            "risk": "The script uses nested loops and integer shifting; the analyst must manually decode it if the script block is not captured.",
            "stage": "execution-clickfix-terminal-paste",
            "question": "what the second-layer PowerShell script performs",
            "requires": "hb_script_activity"
          }
        ],
        "scoping_notes": "Start with all enrolled Windows endpoints. The primary lead is the PowerShell decimal host pattern (e.g., 1614733393).",
        "beyond_detection": "The hunt evaluates cheap decimal-IP leads before running expensive temporal DNS and file-prevalence queries, providing a level of context that a single static rule would miss."
      }
    },
    {
      "id": "scope-potential-targets",
      "type": "query",
      "label": "Scope Windows endpoints",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%powershell%'",
        "surface": "hb_software_inventory",
        "description": "Find the hosts where PowerShell is installed and managed, narrowing the estate for the behavioural lead.",
        "expected_signal": "A list of hosts with PowerShell installed. Silence indicates no software inventory for PowerShell is available."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope Windows endpoints",
        "reads": [
          "device_hostname",
          "package_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%powershell%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with PowerShell installed. Silence indicates no software inventory for PowerShell is available.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "powershell-decimal-ip-lead",
      "type": "query",
      "label": "PowerShell IRM to decimal IP",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%powershell.exe' OR LOWER(process_name) LIKE '%pwsh.exe') AND (process_cmd_line LIKE '%irm %') AND (process_cmd_line LIKE '%' || '{{decimal_ip}}' || '%' OR process_cmd_line GLOB '*[0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]*') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify ClickFix execution where PowerShell uses Invoke-RestMethod (irm) to reach a decimal-encoded IP host.",
        "expected_signal": "PowerShell processes fetching scripts from numeric or decimal host strings. Silence proves no such commands ran in the window."
      },
      "parents": [
        {
          "id": "scope-potential-targets"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "PowerShell IRM to decimal IP",
        "reads": [
          "device_hostname",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%powershell.exe' OR LOWER(process_name) LIKE '%pwsh.exe') AND (process_cmd_line LIKE '%irm %') AND (process_cmd_line LIKE '%' || '{{decimal_ip}}' || '%' OR process_cmd_line GLOB '*[0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]*') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "evidence_of_absence",
        "expected": "PowerShell processes fetching scripts from numeric or decimal host strings. Silence proves no such commands ran in the window.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "assess-lead",
      "type": "analytic",
      "label": "Assess PowerShell lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "powershell-decimal-ip-lead"
        ],
        "objective": "Identify strings in the process command lines that represent decimal-encoded IP addresses and confirm they reach external infrastructure.",
        "description": "Evaluate whether the PowerShell command line matches the ClickFix pattern before running expensive queries.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict of suspicious if the command uses Invoke-RestMethod to reach a decimal host.",
        "success_criteria": "A verdict for each host citing specific command line entries and the resolved IP."
      },
      "parents": [
        {
          "id": "powershell-decimal-ip-lead"
        }
      ]
    },
    {
      "id": "gate-on-lead",
      "type": "checkpoint",
      "label": "Gate on PowerShell lead",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the assess-lead verdict is suspicious or malicious for at least one host",
        "condition": "the assess-lead verdict is suspicious or malicious for at least one host",
        "blind_spot": "visibility-gap",
        "confidence": "high",
        "description": "Stop the hunt if no suspicious PowerShell commands exist, saving resources.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "assess-lead"
        }
      ]
    },
    {
      "id": "dns-lure-redirection",
      "type": "query",
      "label": "DNS lure redirection",
      "config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "source": "endpoint",
        "content": "SELECT device_hostname, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Identify DNS lookups to ChatGPT and Google Sites redirect domains on the suspected hosts.",
        "expected_signal": "DNS requests for the lure domains originating from suspected hosts. Silence says nothing if the domains have rotated."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "enrichment",
        "label": "DNS lure redirection",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "DNS requests for the lure domains originating from suspected hosts. Silence says nothing if the domains have rotated.",
        "verified": "dry-run",
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "msi-file-creation",
      "type": "query",
      "label": "Rare MSI creation in Temp",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT file_name, device_hostname, file_path, time, COUNT(DISTINCT device_hostname) AS host_count FROM hb_file_activity WHERE LOWER(file_path) LIKE '%\\temp\\%' AND LOWER(file_name) LIKE '%.msi' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name HAVING host_count <= 3",
        "surface": "hb_file_activity",
        "description": "Identify the creation of the malicious MSI or other rare installers in temporary directories.",
        "expected_signal": "A stack-count of MSI files; ISOSimple.msi or other rare installers indicate the payload dropped during the ClickFix attack."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare MSI creation in Temp",
        "reads": [
          "file_name",
          "device_hostname",
          "file_path",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT file_name, device_hostname, file_path, time, COUNT(DISTINCT device_hostname) AS host_count FROM hb_file_activity WHERE LOWER(file_path) LIKE '%\\temp\\%' AND LOWER(file_name) LIKE '%.msi' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name HAVING host_count <= 3",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A stack-count of MSI files; ISOSimple.msi or other rare installers indicate the payload dropped during the ClickFix attack.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "file_name"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-30"
      }
    },
    {
      "id": "triage-infection",
      "type": "analytic",
      "label": "Triage infection chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "assess-lead",
          "dns-lure-redirection",
          "msi-file-creation"
        ],
        "objective": "Determine if any host shows the sequence of social engineering redirection, PowerShell execution via decimal host, and subsequent drop of a rare MSI.",
        "description": "Evaluate the combined evidence from PowerShell, DNS, and file activity to confirm the infection.",
        "max_iterations": 5,
        "expected_signal": "A final verdict citing rows from all surfaces to prove the infection chain.",
        "success_criteria": "A final verdict for each host citing evidence from all context steps."
      },
      "parents": [
        {
          "id": "dns-lure-redirection",
          "kind": "merge"
        },
        {
          "id": "msi-file-creation",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-triage",
      "type": "checkpoint",
      "label": "Route infection verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-infection verdict is malicious for at least one host",
        "condition": "the triage-infection verdict is malicious for at least one host",
        "blind_spot": "visibility-gap",
        "confidence": "high",
        "description": "Isolate confirmed infected hosts or route to manual review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-infection"
        }
      ]
    },
    {
      "id": "contain-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Contain the infection to prevent the subsequent DLL sideloading and RAT execution.",
        "instructions": "Isolate the host immediately. Preserve the temporary directory for forensic recovery of the MSI and the 1777.ps1 script.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-triage",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-review",
      "type": "task",
      "label": "Analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Manually confirm the infection if the automated triage was inconclusive.",
        "instructions": "Examine the PowerShell command lines from the lead. Check hb_script_activity for script blocks matching the article's shift-key obfuscation pattern. Verify if any MSI installation occurred under a random GUID name."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "default"
        },
        {
          "id": "gate-on-lead",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-triage",
          "branch": "default"
        },
        {
          "id": "route-on-triage",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-triage",
          "branch": "on_refutes"
        },
        {
          "id": "contain-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Record results and refine search parameters for future runs.",
        "instructions": "Document findings. If decimal IPs are noisy, refine the GLOB pattern to require a more specific digit length. Update the lure domain list."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-review"
        }
      ]
    }
  ]
}