Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.

Threat actors are abusing ChatGPT Custom GPTs as part of a social-engineering campaign that redirects victims to fake verification pages and ultimately installs a remote access trojan (RAT) on Windows systems.
Huntress identified at least 40 incidents associated with the campaign's malicious infrastructure, including two infections confirmed to have originated through attacker-created Custom GPTs.
How the Attack Works
Attackers created Custom GPTs named "Plus 5.6", making them appear similar to legitimate ChatGPT offerings. In some cases, victims reached these GPTs after searching Google for "chatgpt" and clicking a sponsored search result.
Because the malicious GPT was hosted on the legitimate ChatGPT domain, the initial page could appear trustworthy.
When users interacted with it, the GPT displayed a fake "Service Availability Notice" claiming that the primary service had limited availability and directed users to a supposed backup site hosted on Google Sites.
The attack chain can be summarized as:
Sponsored Google Result → Malicious Custom GPT → Google Sites → Fake Cloudflare CAPTCHA → ClickFix → PowerShell → Malicious MSI → DLL Sideloading → RAT
Fake CAPTCHA Triggers ClickFix
The Google Sites page impersonated a Cloudflare CAPTCHA and instructed victims to copy and paste a command into Windows Terminal.
This is a classic ClickFix technique: instead of exploiting a software vulnerability, attackers convince the victim to execute the malicious command themselves.
The PowerShell command downloads and executes a malicious MSI installer, beginning a multi-stage and heavily obfuscated infection chain.
Signed Applications Used for DLL Sideloading
The malware attempts to evade detection by abusing legitimately signed applications.
Huntress observed attackers using a Canon-signed executable (COTFileReadApp.exe) to sideload a malicious DLL. A later version of the campaign switched to a legitimate Stardock-signed executable while delivering the same final RAT.
The infection chain also uses multiple layers of encryption and hides malicious content inside a .wav file before eventually loading the RAT.
Once installed, the malware establishes persistence and provides attackers with continued remote access to the compromised Windows system.
Attackers Quickly Recreated the Malicious GPT
Huntress reported the first malicious Custom GPT to OpenAI, which removed it by September 25, 2026.
However, researchers discovered another Custom GPT connected to the same campaign on September 27, demonstrating how quickly attackers can recreate malicious social-engineering infrastructure.
The campaign highlights an important security issue: users may naturally place more trust in content hosted on well-known platforms such as ChatGPT, Google Sites, or Cloudflare-branded pages.
What Security Teams Should Watch For
Organizations should monitor for:
- Fake CAPTCHA pages requesting terminal commands
- PowerShell launched after browser activity
- Unexpected
msiexec.exeexecutions - Obfuscated PowerShell download commands
- Canon or Stardock executables running from unusual directories
- Suspicious DLL sideloading
- Unexpected scheduled tasks or Registry Run entries
- Unusual DNS-over-HTTPS or outbound network activity
Users should also remember that legitimate CAPTCHA systems do not normally require copying PowerShell or other commands into Windows Terminal.
Security Takeaway
This campaign does not represent a compromise of ChatGPT itself. Instead, attackers abused the ability to create customized GPT experiences and the trust associated with the legitimate ChatGPT domain as part of a broader social-engineering chain.
The attack demonstrates a growing challenge for defenders:
Trusted AI Platform → Social Engineering → ClickFix → User Executes Command → RAT Infection
As attackers increasingly abuse legitimate AI platforms, cloud services, and signed applications, organizations need to evaluate the entire behavioral attack chain rather than trusting individual domains or binaries simply because they belong to reputable services.
Related reporting
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Researchers uncover malicious Terraform providers and Go modules delivering Graphalgo-linked Go malware using Slack and Ethereum blockchain infrastructure for command and control.


