Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Huntress uncovered malicious custom ChatGPT 'Plus 5.6' promoted via Google ads that pushes ClickFix PowerShell payloads installing a full-featured RAT.
Huntress identified a campaign using a malicious custom GPT named 'Plus 5.6', promoted through sponsored Google results, that directs users to a Google Sites page with a fake Cloudflare check instructing victims to run a PowerShell command. The command installs a malicious MSI that launches a signed application with a side-loaded DLL delivering a RAT with remote desktop, camera/audio capture, file search, reconnaissance, and additional payload execution. Persistence uses a Run key and scheduled task both named 'Canon Configuration Reader', with newer attacks switching to a Stardock-signed host and a custom encrypted archive file system concealing the RAT. Huntress linked at least 40 incidents to the Google Sites page; OpenAI took down one GPT on September 25 but a second remained active on September 27.
- Malicious custom GPT 'Plus 5.6' hosted on chatgpt.com lends legitimacy to ClickFix attacks
- PowerShell command installs MSI with DLL side-loading to deploy a RAT
- Persistence via Run key and scheduled task named 'Canon Configuration Reader'
- Custom encrypted file system with 1,128-entry index conceals RAT and persistence script
- At least 40 incidents linked; one GPT removed, second still active
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | chatgpt.com | ks, the malicious instructions are hosted on the legitimate ChatGPT.com domain, lending legitimacy to the operation and increasing |
Full article602 words · extracted from bleepingcomputer.com · click to collapse

Custom variants of OpenAI’s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.
The threat actor is abusing the legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task that combines instructions, extra knowledge, and skills.
OpenAI hosts these custom GPTs, which can be published for others to install and use. The company plans to retire custom GPTs on December 11.
The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.
The threat actor named the malicious GPT model 'Plus 5.6' and configured it to direct users to an alleged backup site hosted on Google Sites.

Source: Huntress
However, the page shows a fake Cloudflare check and instructs visitors to run a PowerShell command, which deploys the infection chain.
Huntress researchers observed similar attacks in the past, which used deceptive ChatGPT conversations to launch ClickFix ruses and compromise targets, but using custom GPTs is a novel approach.
In both attacks, the malicious instructions are hosted on the legitimate ChatGPT.com domain, lending legitimacy to the operation and increasing the chances the victim will follow the instructions.
If executed locally, the provided PowerShell command installs a malicious MSI that launches a legitimate, signed application and a modified DLL loading the malware.
The payload used in this campaign is a remote access trojan (RAT) with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads.
For persistence, the malware creates a new Run key in the Windows Registry and also a scheduled task, both named ‘Canon Configuration Reader.’

Source: Huntress
Huntress says it investigated at least 40 incidents connecting to the Google Sites page but confirmed that only two involved a custom GPT variant.
OpenAI took down the first GPT by September 25. Two days later, on September 27, the researchers found a second GPT linked to the same campaign, which was still active when they published their report.
More recent attacks switched from a Canon-signed host application to a Stardock-signed one and changed how it concealed and delivered the loader, although the payload remained the same.

Source: Huntress
From the multi-stage attack chain, Huntress highlights phase 6, noting that the attackers built a custom encrypted file system to conceal the persistence script and RAT.
“Instead of one encrypted blob, it's a custom archive with its own folder tree, basically a homemade, encrypted zip file,” researchers say.
“It starts with a small header, followed by an index of 1,128 entries (one per file or folder, each recording its parent, its size and a per-file key), and then the file contents, packed back to back.”
Huntress says that most of the infection chain runs in memory or is supported by files that appear benign. This allows defenders to implement detections based on process activity monitoring.
The researchers provide a set of "detection opportunities" that include PowerShell pinging msiexec.exe to silently launch an MSI installer from the temporary folder.
Additional signs of compromise refer to a signed app starting from an unusual folder under %LOCALAPPDATA%\Programs\, and a matching Run value and scheduled task that reappear if deleted.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.