Attack Flow Steps:
: Attacker-created Custom GPT page on the legitimate ChatGPT domain, promoted via a paid Google Ad, used as the initial social-engineering lure.. : Victims searched Google for 'chatgpt', clicked a sponsored ad leading to the attacker-created Custom GPT page, which then delivered a fake service-availability notice pointing to a 'backup domain'.. : New Custom GPT discovered on September 27 after the first instance was taken down, linked to the same campaign.. : Google Sites page presented as a Cloudflare CAPTCHA check, delivering a ClickFix attack instructing users to paste a command into Terminal.. : The Google Sites page tricked victims into copying and pasting a command into their Windows Terminal to resolve a fake CAPTCHA/availability issue.. : Execution of an obfuscated PowerShell one-liner that downloads and runs a script via irm, bypassing execution policy.. : Delivery server addressed as a decimal number to evade dotted-IP filters; hosts the ClickFix script and the MSI.. : Obfuscated PowerShell stager written to %TEMP% under a random filename; double-layer XOR/integer encoding hides the download URL and commands.. : The dropped script uses two layers of integer-array XOR-style encoding so download URLs and API calls never appear in plain text, and decoded code is run via scriptblock::Create without touching disk.. : The decoded script downloads the malicious MSI (ISOSimple.msi) over HTTP from the decimal-IP host, saved under a fresh GUID each time.. : Used to silently install the malicious MSI package with /qn /norestart in a hidden window.. : Malicious MSI masquerading as 'Advanced Printer Configuration Reader' from publisher 'Softplicity'; installs silently, hides from Programs and Features, and launches COTFileReadApp.exe via a custom action.. : End-user Windows workstation targeted by the campaign; at least 40 incidents were traced to this attack chain.. : The legitimate Canon-signed COTFileReadApp.exe loads a patched Canon logging DLL (ceiinfolog.dll) whose import table was modified to pull in the malicious rdCore.dll, using Windows' folder-first DLL search order.. : Legitimate, Canon-signed application from CaptureOnTouch, abused as the host process to sideload malicious DLLs.. : A real Canon DLL, modified and patched to import rdCore.dll, with its signature stripped and header checksum no longer matching contents.. : Malicious, unsigned DLL disguised with Polly 7.2.3 version information; extracts and runs the loader hidden inside the .wav file.. : Malicious DLLs (rdCore.dll, WPFLocalizeExtension.dll) borrow the names and fake version information of real open-source libraries (Polly, WPFLocalizeExtension) to blend in during file inspection.. : Malicious, unsigned native DLL borrowing the name of a real open-source .NET library; provides helper exports used to allocate and execute memory for the loader.. : Malicious, unsigned helper DLL loaded by rdCore.dll before the payload runs.. : Audio file with a valid WAV header whose later portion is overwritten with ciphertext carrying an encrypted loader, read at offset 0x24362.. : The loader shellcode is hidden within a .wav audio file by overwriting a stretch of real audio samples with XOR-encrypted ciphertext, defeating file-header-based detection.. : rdCore.dll reads bytes from the .wav and decodes them with a rolling single-byte XOR algorithm where two counters are stirred on every byte, revealing x64 loader shellcode.. : The loader shellcode performs an AMSI bypass aimed at amsi.dll to blind antivirus inspection of in-memory scripts and .NET code.. : The loader maps a fresh copy of ntdll.dll to remove EDR hooks placed in the loaded module for monitoring.. : The loader performs anti-VM checks against CPU vendor strings and a long list of VMware, VirtualBox, Hyper-V, QEMU, Xen and Parallels drivers and services, and shows a fake 'LOADING...' window as a decoy.. : Encrypted custom archive/file system with 1,128 indexed entries holding the persistence script and the RAT, encrypted with a master key plus per-entry salt and per-file XOR keys.. : A shutdown monitor and periodic check re-create the HKCU Run key 'Canon Configuration Reader' every 150 seconds if removed, launching COTFileReadApp.exe for persistence.. : A scheduled task named 'Canon Configuration Reader' is recreated every 875 seconds if deleted, and the block_execution task pulls the @input resource and runs it from memory.. : 1.58 MB final payload shellcode extracted from monitor.raw; a full-featured RAT providing remote control, collection, discovery, and follow-on payload execution capabilities.. : The RAT can capture the endpoint's camera input as part of its hands-on control features.. : The RAT can capture microphone and system audio input from the infected host.. : The RAT runs remote desktop sessions and screen 'broadcasts' for hands-on operator control.. : The RAT documents domain and domain controller details, network adapters, open ports, installed software, activated Windows features, and a detailed hardware fingerprint.. : The RAT enumerates installed antivirus products through WMI calls and checks Microsoft Defender status.. : The RAT locates its C2 server, called the 'Gate,' using DNS-over-HTTPS through Cloudflare, Google, and Quad9 resolvers so lookups never appear in local DNS logs.. : Legitimately signed application (GOM & Company) dropped by the RAT into %LOCALAPPDATA%\AppstorageFile\, which then launched chrome.exe with a throwaway browser profile.. : The RAT can drop and run follow-on payloads (EXE, DLL via rundll32/regsvr32, MSI, PowerShell, Batch, VBScript, JScript, ZIP) embedded or downloaded from a URL silently in the background.. : Payload server observed in a related incident; delivery infrastructure varied between incidents.. : A third installer hosted on the same delivery server the same day the Canon wave started, indicating other signed applications are likely being abused the same way.. : URL used in version 2 of the campaign for the second-stage script, freshly obfuscated on every request via the decimal-IP host.. : Version 2's malicious installer, presenting as 'Stardock Smart DeElevation Tool'.. : Legitimate Stardock-signed binary abused in version 2 as the host process for DLL side-loading, replacing COTFileReadApp.exe.. : Patched Stardock DLL used in version 2, imports the malicious I++u.dll loader.. : Version 2 loader DLL disguising itself with fake SharpCompress version information.. : Loader hidden inside the compressed data of a genuine Microsoft NuGet package, replacing the WAV steganography method used in version 1.. : Version 2's download flow strips the Mark-of-the-Web from the MSI before running it, letting it run without SmartScreen 'file came from the internet' warnings.. : Version 2's encrypted archive equivalent to monitor.raw, holding the persistence script and RAT.. : URL used to download the version 2 MSI installer (IconEdit2Turb.msi) from the decimal-IP host.
MITRE ATT&CK Techniques:
- T1189
- T1204.004
- T1059.001
- T1027
- T1105
- T1574.002
- T1036.005
- T1027.003
- T1140
- T1562.001
- T1497
- T1547.001
- T1053.005
- T1125
- T1123
- T1113
- T1082
- T1518.001
- T1071.004
- T1553.005