Attackers Weaponize ChatGPT Custom GPTs to Deploy RATs via ClickFix

4 min read
Source: The Hacker News
Attackers Weaponize ChatGPT Custom GPTs to Deploy RATs via ClickFix
Photo: The Hacker News
TL;DR

Threat actors are abusing ChatGPT Custom GPTs to deliver remote access trojans (RATs) through ClickFix lures. Huntress identified a campaign where malicious GPTs, hosted on the legitimate chatgpt.com domain, redirect users to fake Cloudflare CAPTCHA pages. These pages trick victims into executing PowerShell commands that install malware. The infection chain uses signed binaries to sideload malicious DLLs, ultimately deploying a RAT capable of data theft, surveillance, and network persistence. At least 40 users have been infected, with the initial entry point often being sponsored Google ads for 'chatgpt'.

Key points

  • Huntress observed a campaign in late September 2026 where attackers created Custom GPTs named 'Plus 5.6' to mimic official OpenAI products.
  • Victims interacting with these GPTs are shown a 'Service Availability Notice' directing them to a backup Google Sites domain due to 'limited availability'.
  • The backup domain presents a fake Cloudflare CAPTCHA that triggers a ClickFix attack, forcing users to paste a malicious PowerShell command.
  • The command downloads an MSI installer that abuses a Canon-signed binary to sideload a rogue DLL, which extracts an encrypted loader from a .WAV audio file.
  • The final payload is a RAT that bypasses AMSI, unhooks ntdll.dll, and performs anti-virtual machine checks to avoid detection.
  • The RAT features include remote desktop sessions, camera/microphone capture, file searching, and the ability to drop secondary payloads.

Background

This incident follows a trend of ClickFix attacks becoming mainstream, as noted in our September 2026 coverage, where fake CAPTCHA tactics bypassed security protections on Windows and macOS. Additionally, a recent ChatGPT outage in August 2026 highlighted the platform's critical role in enterprise workflows, making its features, like Custom GPTs, attractive targets for social engineering. The current campaign exploits the trust users place in the official ChatGPT domain and the perceived legitimacy of AI-generated content.

How outlets are covering it

Huntress provides the most detailed technical breakdown, emphasizing the multi-stage infection chain and the specific evasion techniques used by the RAT, such as DLL sideloading and AMSI bypass. They highlight the social engineering aspect, noting that victims often arrive via sponsored Google ads. Dark Reading focuses on the implications for security awareness training, arguing that the trusted domain (chatgpt.com) is no longer a reliable safety signal, and users must be trained to scrutinize the actions requested by any interface. Cybernews offers a broader view of the malvertising landscape, citing Island's research on 850 paid-ad landings and 26 lookalike destinations, but does not provide the same level of technical detail on the malware's capabilities as Huntress. TechRadar's source was largely obscured by website code, offering no substantive analysis. The outlets agree on the core mechanism (ClickFix via Custom GPTs) but differ in emphasis: Huntress on technical evasion, Dark Reading on user behavior, and Cybernews on the scale of the ad campaign.

Why it matters

This campaign demonstrates a significant escalation in AI platform abuse, moving from shared conversations to the exploitation of the official ChatGPT domain itself. The use of Custom GPTs, a feature designed for legitimate business and personal use, to host malicious lures undermines user trust in AI platforms. The sophisticated evasion techniques, including the use of signed binaries and DNS-over-HTTPS, make detection and prevention more challenging for traditional security tools. Organizations must update their security awareness training to focus on the actions requested by users, rather than just the source of the request, as trusted domains are increasingly being abused for malicious purposes.

What to watch

Security teams should monitor for the specific indicators of compromise provided by Huntress, including the malicious MSI installer and the altered Canon DLL. Organizations should review their Custom GPT usage and ensure that any GPTs are from trusted sources. User awareness training should be updated to emphasize that no legitimate service will ask users to paste commands into PowerShell or Terminal to verify their identity. Additionally, defenders should look for signs of the RAT's capabilities, such as unexpected remote desktop sessions or camera/microphone access, and ensure that their endpoint detection and response (EDR) solutions are configured to detect the specific evasion techniques used by this malware.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News