Hackers Weaponizing ChatGPT’s Custom GPT Feature to Trick Victims into Installing Malware
Huntress details a ClickFix campaign abusing ChatGPT Custom GPTs to push obfuscated PowerShell, malicious MSI, and DLL sideloading into a full-featured RAT.
Huntress investigated at least 40 incidents where a malicious Custom GPT named 'Plus 5.6' redirected users to a Google Sites fake CAPTCHA page instructing them to paste a PowerShell command; the script encoded its C2 IP as decimal 1614733393 (96.62.224.81) and silently installed ISOSimple.msi. The MSI launched Canon-signed COTFileReadApp.exe, which sideloaded a modified ceiinfolog.dll pulling rdCore.dll and extracting an encrypted loader from a WAV file, with AMSI bypass, ntdll unhooking, and anti-VM checks before in-memory .NET RAT execution. The RAT persists via an HKCU Run key and scheduled task, supports remote desktop, camera/microphone capture, file search, and additional payload execution, and resolves C2 via DNS-over-HTTPS. After OpenAI removed the GPT, a replacement used Stardock-signed DeElevate64.exe and a NuGet-packaged loader with Mark-of-the-Web stripped.