Skip to main content
The Wire
CyberNews by Zentrya One
Malware

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix

Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.

Threat actors are abusing ChatGPT Custom GPTs as part of a social-engineering campaign that redirects victims to fake verification pages and ultimately installs a remote access trojan (RAT) on Windows systems.

Huntress identified at least 40 incidents associated with the campaign's malicious infrastructure, including two infections confirmed to have originated through attacker-created Custom GPTs.

How the Attack Works

Attackers created Custom GPTs named "Plus 5.6", making them appear similar to legitimate ChatGPT offerings. In some cases, victims reached these GPTs after searching Google for "chatgpt" and clicking a sponsored search result.

Because the malicious GPT was hosted on the legitimate ChatGPT domain, the initial page could appear trustworthy.

When users interacted with it, the GPT displayed a fake "Service Availability Notice" claiming that the primary service had limited availability and directed users to a supposed backup site hosted on Google Sites.

The attack chain can be summarized as:

Sponsored Google Result → Malicious Custom GPT → Google Sites → Fake Cloudflare CAPTCHA → ClickFix → PowerShell → Malicious MSI → DLL Sideloading → RAT

Fake CAPTCHA Triggers ClickFix

The Google Sites page impersonated a Cloudflare CAPTCHA and instructed victims to copy and paste a command into Windows Terminal.

This is a classic ClickFix technique: instead of exploiting a software vulnerability, attackers convince the victim to execute the malicious command themselves.

The PowerShell command downloads and executes a malicious MSI installer, beginning a multi-stage and heavily obfuscated infection chain.

Signed Applications Used for DLL Sideloading

The malware attempts to evade detection by abusing legitimately signed applications.

Huntress observed attackers using a Canon-signed executable (COTFileReadApp.exe) to sideload a malicious DLL. A later version of the campaign switched to a legitimate Stardock-signed executable while delivering the same final RAT.

The infection chain also uses multiple layers of encryption and hides malicious content inside a .wav file before eventually loading the RAT.

Once installed, the malware establishes persistence and provides attackers with continued remote access to the compromised Windows system.

Attackers Quickly Recreated the Malicious GPT

Huntress reported the first malicious Custom GPT to OpenAI, which removed it by September 25, 2026.

However, researchers discovered another Custom GPT connected to the same campaign on September 27, demonstrating how quickly attackers can recreate malicious social-engineering infrastructure.

The campaign highlights an important security issue: users may naturally place more trust in content hosted on well-known platforms such as ChatGPT, Google Sites, or Cloudflare-branded pages.

What Security Teams Should Watch For

Organizations should monitor for:

  • Fake CAPTCHA pages requesting terminal commands
  • PowerShell launched after browser activity
  • Unexpected msiexec.exe executions
  • Obfuscated PowerShell download commands
  • Canon or Stardock executables running from unusual directories
  • Suspicious DLL sideloading
  • Unexpected scheduled tasks or Registry Run entries
  • Unusual DNS-over-HTTPS or outbound network activity

Users should also remember that legitimate CAPTCHA systems do not normally require copying PowerShell or other commands into Windows Terminal.

Security Takeaway

This campaign does not represent a compromise of ChatGPT itself. Instead, attackers abused the ability to create customized GPT experiences and the trust associated with the legitimate ChatGPT domain as part of a broader social-engineering chain.

The attack demonstrates a growing challenge for defenders:

Trusted AI Platform → Social Engineering → ClickFix → User Executes Command → RAT Infection

As attackers increasingly abuse legitimate AI platforms, cloud services, and signed applications, organizations need to evaluate the entire behavioral attack chain rather than trusting individual domains or binaries simply because they belong to reputable services.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.