New ChatGPT Campaign Tricks Users with Custom GPTs, Delivers RATs
A sophisticated cyber attack campaign has been uncovered by cybersecurity firm Huntress, which uses customized versions of ChatGPT to trick users into downloading remote access Trojans (RATs). This clever tactic leverages the trust in OpenAI’s and Google’s legitimate domains to direct unsuspecting victims to malicious sites. The campaign, reminiscent of ClickFix-style attacks, has already affected dozens of users.
Here’s how it works: attackers create customized ChatGPT instances that mimic real product offerings, such as personal research assistants or customer-facing support tools. These Custom GPTs are designed to look like official OpenAI releases and are served through the legitimate ChatGPT domain. When a user interacts with these fake ChatGPT instances, they’re presented with a prompt warning them that the service is unavailable, suggesting an upgrade to a premium subscription or directing them to a “backup” domain hosted on Google Sites.
The “backup” link leads to a fake Cloudflare landing page featuring a CAPTCHA challenge. After completing the CAPTCHA, victims are served a standard ClickFix-style prompt instructing them to execute a PowerShell command. This command downloads an MSI file that uses a legitimate Canon-signed application to sideload malicious DLLs. These DLLs then extract and execute an encrypted loader hidden in a WAV file, which ultimately retrieves and unpacks the RAT.
The RAT’s primary goal is to establish a persistent foothold within an organization’s environment, allowing attackers to engage in data theft, extortion-based attacks, espionage, or other malicious activities. In some cases, the RAT may be followed by additional malware installations, designed to steal browser data and map out the victim’s endpoint.
Huntress has identified two Custom GPT instances being used in this campaign, with their security operations center (SOC) responding to at least 40 incidents stemming from a specific Google Sites domain. Mark O’Halloran and Jonathan Semon, the researchers behind the discovery, stress that this campaign highlights the importance of staying vigilant against social engineering tactics.
To avoid falling victim to similar attacks, users should remain cautious when interacting with unfamiliar or customized versions of popular services like ChatGPT. It’s essential to verify the authenticity of any service or domain before providing sensitive information or executing system commands. Additionally, organizations should prioritize robust security measures, including regular software updates and employee education on social engineering tactics.
Ultimately, this campaign serves as a reminder that even the most sophisticated cyber attacks can be launched through seemingly innocuous means. As we continue to rely on AI-powered tools like ChatGPT for various tasks, it’s crucial to acknowledge the potential risks associated with these technologies and take proactive steps to protect ourselves against emerging threats.
Source: Dark Reading — 2026-09-30