Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Malicious Custom ChatGPTs Spread ClickFix Attacks, Delivering RAT Malware to Unsuspecting Users

A new wave of cyber threats has emerged in the form of custom ChatGPT variants, which are being used to launch sophisticated attacks against unsuspecting users. These malicious versions of OpenAI’s popular AI platform have been promoted through sponsored Google results and are directing victims to sites that use ClickFix attacks to deliver remote access trojans (RATs).

The attackers are exploiting the legitimate feature in ChatGPT that allows users to create custom variants for specific tasks, combining instructions, knowledge, and skills. OpenAI hosts these custom GPTs, which can be published by others to install and use. However, the company has announced plans to retire custom GPTs on December 11.

Researchers at Huntress, a managed detection and response (MDR) company, have identified dozens of users affected by this malicious campaign. The threat actors have named their malicious GPT model “Plus 5.6” and configured it to direct victims to an alleged backup site hosted on Google Sites. However, upon arrival, the page displays a fake Cloudflare check and instructs visitors to run a PowerShell command, which sets off the infection chain.

The attack involves several stages, with the malicious instructions being hosted on the legitimate ChatGPT.com domain to lend legitimacy to the operation. If executed locally, the provided PowerShell command installs a malicious MSI that launches a legitimate, signed application and a modified DLL loading the malware. The payload used in this campaign is a RAT with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads.

For persistence, the malware creates a new Run key in the Windows Registry and also a scheduled task, both named “Canon Configuration Reader.” Huntress researchers observed similar attacks in the past that used deceptive ChatGPT conversations to launch ClickFix ruses and compromise targets. However, using custom GPTs is a novel approach, making it more challenging for defenders to detect.

The malware’s persistence mechanism involves creating a custom encrypted file system to conceal the persistence script and RAT. Huntress researchers highlighted phase 6 of the attack chain, noting that the attackers built a homemade, encrypted zip file with its own folder tree. This allows defenders to implement detections based on process activity monitoring, as most of the infection chain runs in memory or is supported by files that appear benign.

To mitigate this threat, defenders should focus on detecting PowerShell pinging msiexec.exe to silently launch an MSI installer from the temporary folder. Additional signs of compromise include a signed app starting from an unusual folder under %LOCALAPPDATA%\Programs\ and a matching Run value and scheduled task that reappear if deleted. By staying vigilant and implementing effective detection mechanisms, users can protect themselves against these sophisticated attacks.

In light of this threat, it’s essential for organizations to prioritize security measures, including monitoring process activity, scanning for suspicious files, and implementing robust detection mechanisms. As AI-powered attacks continue to evolve, defenders must adapt their strategies to stay ahead of the threats.


Source: Bleeping Computer — 2026-09-29