Custom ChatGPTs push ClickFix attacks to deploy RAT malware

A malicious campaign has been uncovered, using custom variants of OpenAI’s popular chatbot platform, ChatGPT, to deploy remote access trojans (RAT) malware. The threat actors are exploiting the legitimate feature in ChatGPT that allows users to create custom versions of the AI for specific tasks, and hosting these malicious models on Google Sites. The attackers are then using ClickFix attacks, which involve inserting malicious instructions into a chat conversation, to trick victims into downloading and installing the malware.

The campaign was identified by Huntress, a managed detection and response company, who observed dozens of users being affected. The threat actors named their malicious GPT model ‘Plus 5.6’, which directed users to an alleged backup site hosted on Google Sites. However, upon arrival, visitors were presented with a fake Cloudflare check and instructed to run a PowerShell command that initiated the infection chain.

Here’s how it works: when victims execute the provided PowerShell command locally, they install a malicious MSI that launches a legitimate, signed application alongside a modified DLL that loads the malware payload. The payload itself is a RAT with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads.

What’s notable about this campaign is its use of custom GPTs to deliver the malware. This approach allows the attackers to create multiple versions of the malicious model, each tailored to evade detection by security software. The threat actors also employed a novel tactic of using a signed application as a host for the malware payload, which increases the chances that the victim will trust the installation.

The researchers at Huntress have identified several “detection opportunities” that defenders can use to identify potential compromises. These include monitoring PowerShell activity for silent launches of MSI installers from temporary folders, and looking out for signed applications starting from unusual locations under %LOCALAPPDATA%\Programs\.

This campaign highlights the evolving nature of threats in the AI-powered attack landscape. As AI platforms like ChatGPT become increasingly popular, attackers are finding new ways to exploit their features. To stay ahead, defenders need to be aware of these novel tactics and adapt their detection strategies accordingly.

In practical terms, this means that users should exercise caution when encountering custom GPTs or being directed to suspicious sites through chat conversations. It’s also essential for security professionals to stay informed about the latest threats and adjust their defenses to account for emerging tactics like this one. By doing so, we can work together to prevent these types of attacks from succeeding in the future.


Source: Bleeping Computer — 2026-09-29