Malicious Custom ChatGPTs Push ClickFix Attacks to Deploy RAT Malware
AI

Malicious Custom ChatGPTs Push ClickFix Attacks to Deploy RAT Malware

TechNews Editorial
TechNews EditorialSep 30, 2026 · 2 min read
Share

Why it matters

This campaign highlights how threat actors abuse legitimate AI platform features and trusted domains to deceive users into installing sophisticated remote access trojans.

The facts

  • Attackers are promoting custom ChatGPT models in sponsored Google results to push ClickFix attacks.
  • The malicious GPT models direct users to Google Sites pages displaying fake Cloudflare checks and PowerShell commands.
  • The resulting infection chain deploys a remote access trojan with extensive system reconnaissance capabilities.

Threat actors are using custom variants of OpenAI's ChatGPT promoted in sponsored Google results to direct users to malicious sites. These sites use ClickFix attacks to deliver malware.

The threat actor abuses a legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task. OpenAI hosts these custom GPTs, which can be published for others to install and use. OpenAI plans to retire custom GPTs on December 11.

Researchers uncovered custom GPT malware

Managed detection and response company Huntress identified the malicious campaign, which affected dozens of users. The threat actor named the malicious GPT model Plus 5.6. The model directs users to an alleged backup site hosted on Google Sites.

The page shows a fake Cloudflare check and instructs visitors to run a PowerShell command. This command deploys the infection chain. Huntress previously observed attacks using deceptive ChatGPT conversations to launch ClickFix ruses, but using custom GPTs is a novel approach.

A user follows a counterfeit verification prompt and runs a command that starts downloading malicious software.
Illustration: AI & Tech News

Malicious instructions leverage trusted domains

The malicious instructions are hosted on the legitimate ChatGPT.com domain in both attacks. This lends legitimacy to the operation and increases the chances victims will follow the instructions.

If executed locally, the PowerShell command installs a malicious MSI. This MSI launches a legitimate, signed application and a modified DLL loading the malware.

Read nextUK AI Security Institute warns GPT-6 Astra excels at supply chain attacks

Attackers deployed a remote access trojan

The payload is a remote access trojan with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads. For persistence, the malware creates a new Run key in the Windows Registry and a scheduled task named Canon Configuration Reader.

Huntress investigated at least 40 incidents connecting to the Google Sites page. The firm confirmed that only two involved a custom GPT variant. OpenAI took down the first GPT by September 25. Researchers found a second GPT linked to the same campaign on September 27, which was still active when they published their report.

More recent attacks switched from a Canon-signed host application to a Stardock-signed one and changed how it concealed and delivered the loader, though the payload remained the same. Huntress highlights phase six of the multi-stage attack chain, noting that attackers built a custom encrypted file system to conceal the persistence script and RAT.

Huntress says most of the infection chain runs in memory or is supported by files that appear benign. The researchers provide detection opportunities, including PowerShell pinging msiexec.exe to silently launch an MSI installer from the temporary folder. Additional signs of compromise include a signed app starting from an unusual folder under local app data programs, and a matching Run value and scheduled task that reappear if deleted.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading