Back to Feed
MalwareSep 30, 2026

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Attackers abuse ChatGPT Custom GPTs to deliver RATs via fake product lures.

Summary

Threat actors are exploiting ChatGPT Custom GPTs to impersonate legitimate offerings and lure victims to malicious sites. These sites use ClickFix lures to deliver malware, specifically a RAT, through a complex MSI installer chain involving DLL sideloading and shellcode execution. Huntress observed at least 40 users infected by this campaign.

Full text

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures Ravie LakshmananSep 30, 2026Malware / Artificial Intelligence Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs). Custom GPTs refer to a personalized version of ChatGPT that, as the name implies, allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. They are hosted on the legitimate ChatGPT website with the Custom GPT name at the top. "In the incidents we saw, victims interacted with an attacker-created Custom GPT, which was programmed to respond to their prompts with a message that included a Google Sites link," Huntress said. "This link then brought them to a ClickFix-style attack, which led to the download and execution of a malicious MSI installer." The installer then initiates a DLL sideloading chain responsible for loading shellcode, which is used to launch a persistence script and a RAT payload. No less than 40 users have been infected as part of the campaign. The starting point of the attack is a sponsored result for searches like "chatgpt" on Google. The two Custom GPT links are listed below - chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6 chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6 Users who end up interacting with the Custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain." To nudge unsuspecting users into opting for the latter option, the notice also displays the message: "We recommend using the backup domain if you need immediate access." Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command. The PowerShell command is used to deploy an MSI installer ("ISOSimple.msi"), which abuses a legitimate Canon-signed binary ("COTFileReadApp.exe") to sideload a rogue DLL ("ceiinfolog.dll"). The DLL, per Huntress, is the real Canon DLL that's been altered to load a second, unsigned DLL ("rdCore.dll"), which subsequently extracts an encrypted loader from a .WAV audio file ("Common.Integrator.Preview.wav"). While this is not the first time threat actors have smuggled their payload within audio and video file formats, WAV-hidden payloads have been previously observed in connection with Octowave Loader campaigns. In the final stage, the loader shellcode proceeds to unpack the trojan and a persistence script from an encrypted file system ("monitor.raw"), but not before bypassing AMSI, unhooking "ntdll.dll" to sidestep user-mode monitoring by security programs, and running anti-virtual machine checks by checking CPU vendor strings against various VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services. The trojan supports a wide range of features - Documents installed antivirus, Microsoft Defender status, and system profile Runs remote desktop sessions and screen "broadcasts." Captures the endpoint's camera input, the microphone, and system audio. Recognizes 17 web browsers and can launch the default one. Searches file contents across the system using a built-in file manager component. Drops and runs secondary payloads (i.e., .EXE, .DLL, and .MSI) and scripts (i.e., PowerShell, batch, VBScript, and JavaScript) "To find its C2 server, which the strings call the 'Gate,' the RAT uses DNS-over-HTTPS through Cloudflare, Google, and Quad9 servers," Huntress said. "Its lookups travel inside ordinary HTTPS traffic to well-known resolvers, so they never appear in local DNS logs." It's suspected the server details are hidden deep inside the code in an encrypted form or retrieved at runtime. The RAT malware has been consistently found to drop a legitimately signed binary ("GOMCam2024.exe") that launches Google Chrome with a throwaway browser profile located in the "%TEMP%" directory. "Overall, threat actors continue to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT's Custom GPT feature or through Google Sites for hosting a ClickFix attack," Huntress said. The findings coincide with the discovery of multiple ClickFix-oriented campaigns in the wild - Using phishing websites hosted on Google Sites that mimic OpenAI Codex and Anthropic Claude to establish trust and serve a fake installation prompt, which uses ClickFix to distribute and execute stealer malware directly in memory. The stealer can fingerprint the host and contact an external domain to fetch next-stage payloads to conduct data and cryptocurrency wallet theft. A likely compromised website that uses EtherHiding to fetch JavaScript that serves a ClearFake reCAPTCHA verification prompt to coerce victims into running a malicious command that opens a WebDAV path and retrieves a DLL. The DLL payload initiates a multi-stage process to drop Amatera Stealer. The stealer, besides siphoning sensitive data, runs three secondary payloads: a NativeAOT loader, ZigCryptoStealer, and a Go reverse TCP proxy. Another build of the stealer has been found to install NetSupport Manager. Some of these attacks have targeted Ukrainian government systems and are attributed to a Russia-aligned activity cluster that's tracked as UAT-10820. Using malvertising, phishing emails, and a compromised retail website to direct users to a fake Cloudflare interstitial page staged on a bulletproof hosting provider (AS202412, registered to Seychelles-based OMEGATECH LTD) to deliver malicious payloads, including a trojanized installer that drops an infostealer, a Node.js implant, and a batch script that establishes persistence through a Windows Active Setup registry key. A ClickFix campaign that has been active since at least November 2025 and uses a cluster of 31 compromised business websites to display a fake CAPTCHA lure that delivers a dropper, which then executes a PowerShell script to set up persistence and a C2 agent that employs EtherHiding by querying the Polygon blockchain to identify the C2 server and then uses it to receive and execute arbitrary PowerShell commands. "What began as a general-purpose remote-access backdoor has since been observed delivering a real-time banking trojan capable of intercepting login credentials and two-factor codes from major banks and cryptocurrency exchanges as victims type them," GuidePoint Security said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, malvertising, Malware, Social Engineering, Windows Security ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a

Indicators of Compromise

  • malware — ISOSimple.msi
  • malware — COTFileReadApp.exe
  • malware — ceiinfolog.dll
  • malware — rdCore.dll
  • malware — Common.Integrator.Preview.wav
  • malware — monitor.raw

Entities

ChatGPT (product)Custom GPTs (technology)AI (technology)Huntress (vendor)Cloudflare (product)