A new social engineering campaign is hijacking the popularity of ChatGPT, using paid Google ads to direct users to malicious sites that deploy Remote Access Trojan (RAT) malware through a deceptive "troubleshooting" prompt.

Attackers are creating fake websites that mimic custom GPTs, promoting them via sponsored search results to lend an air of legitimacy. When victims land on these sites, they are presented with an apparent technical error, prompting them to apply a "quick fix."

This fix leverages the ClickFix technique: users are instructed to copy a provided command, open a command-line interface like PowerShell, and paste the command to resolve the issue. This method bypasses conventional security warnings about downloads or malicious links. Once the command is executed, it secretly downloads and installs the RAT malware, granting attackers remote control over the compromised system.

The campaign's effectiveness stems from its layered manipulation. It exploits the inherent trust in the ChatGPT brand and the perceived credibility of Google's advertising platform. Most critically, it subverts standard security awareness by turning the user into the active installer, manually initiating the infection as part of a false resolution step.

For Hong Kong IT teams, this represents a clear case study in the evolving threat landscape surrounding AI tool adoption. The core lesson is the rise of "malicious instruction" social engineering, where user training must go beyond spotting bad links.

Actionable Defensive Strategies for Organizations:

  • Enforce Vetted AI Tool Policies: Establish clear guidelines directing staff to use only officially sanctioned AI platforms. Technical controls such as DNS filtering can help block access to known malicious domains masquerading as AI services.
  • Evolve Security Training: Update awareness programs to specifically address ClickFix and similar tactics. Conduct simulations where employees are tempted with fake "copy-paste commands" to test and reinforce proper response protocols.
  • Strengthen Endpoint Detection: Enhance monitoring with EDR solutions capable of behavioral analysis. Pay close attention to alerts involving unusual PowerShell or script executions, particularly those initiated manually by a user.
  • Apply Least Privilege: Limit user administrative rights on local systems to contain the potential damage from a successful RAT installation.

As excitement around generative AI persists, attackers are refining their methods to exploit it. This campaign underscores that defending against such threats requires both informed users and robust, layered technical safeguards.


一場新的社會工程攻擊活動正利用ChatGPT的熱度,透過付費Google廣告將用戶引導至惡意網站,並透過一個欺詐性的「故障排除」提示,部署遠端存取木馬(RAT)惡意軟件。

攻擊者正在建立模仿自訂GPT的虛假網站,並透過贊助搜尋結果推廣它們,藉此賦予其合法的外觀。當受害者造訪這些網站時,會看到一個明顯的技術錯誤提示,促使他們套用一個「快速修復」方案。

此修復方案利用了ClickFix技巧:用戶被指示複製一個提供的指令、開啟像PowerShell這樣的命令列介面,然後貼上該指令以解決問題。這種方法繞過了針對下載或惡意連結的傳統安全警告。一旦指令被執行,它會秘密地下載並安裝RAT惡意軟件,讓攻擊者取得對受感染系統的遠端控制權。

該攻擊活動的有效性源於其多層次的操縱手法。它利用了對ChatGPT品牌的固有信任,以及Google廣告平台被認為具有的可信度。最關鍵的是,它顛覆了標準的安全意識,將用戶變成了主動的安裝者,手動啟動感染過程作為虛假修復步驟的一部分。

對香港的IT團隊而言,這清楚地說明了圍繞採用AI工具不斷演變的威脅格局。核心教訓是「惡意指令」社會工程的興起,這意味著用戶培訓必須超越僅僅識別惡意連結的層面。

組織的實用防禦策略:

  • 強制執行經審核的AI工具政策: 制定明確指引,指示員工僅使用官方認可的AI平台。DNS過濾等技術控制措施有助於阻止訪問偽裝成AI服務的已知惡意網域。
  • 提升安全意識培訓: 更新意識教育計劃,以具體應對ClickFix及類似手法。進行模擬演練,向員工提供虛假的「複製貼上指令」以測試並強化正確的應對協議。
  • 加強端點偵測: 利用具備行為分析能力的EDR解決方案來增強監控。密切關注涉及異常PowerShell或腳本執行的警報,尤其是那些由用戶手動觸發的。
  • 套用最小權限原則: 限制用戶在本地系統上的管理員權限,以限制成功安裝RAT所可能造成的損害。

隨著圍繞生成式人工智能的熱度持續,攻擊者正在改進其利用此熱度的方法。此攻擊活動強調,防禦此類威脅既需要具備資訊安全意識的用戶,也需要強健、多層次的技術防護措施。

新聞來源 / Original News Source