Back to all lessons
Awareness Lessons
2 weeks ago

Fake ChatGPT Custom GPT Delivers RAT via Eight-Stage ClickFix Attack

Threat actors are abusing the trust users place in legitimate platforms — ChatGPT and Google Sites — to disguise a sophisticated malware delivery chain. By hosting a malicious Custom GPT on OpenAI's own domain, attackers exploit perceived legitimacy to trick victims into voluntarily executing a PowerShell command, bypassing technical controls through social engineering. The eight-stage chain uses obfuscation, DLL sideloading, and MSI abuse to evade detection and deploy a fully featured RAT. This attack demonstrates that platform trust is not a security guarantee, and that end-user awareness of command-execution prompts is a critical last line of defence.

Tactical Insight

Immediate actions

  • Block or restrict PowerShell execution for standard users via Group Policy or endpoint management tools.
  • Enforce application control policies (e.g., AppLocker or WDAC) to prevent unsigned MSI and DLL execution.

Security awareness measures

  • Train users to never copy-paste or execute terminal/PowerShell commands prompted by a website, AI tool, or chatbot, regardless of how trusted the platform appears.
  • Publish internal guidance specifically warning staff about ClickFix-style social engineering lures that masquerade as legitimate AI services.

Detection measures

  • Deploy endpoint detection and response (EDR) tooling with rules to alert on suspicious PowerShell execution chains, MSI installs from temp directories, and DLL sideloading patterns.
  • Monitor outbound network traffic for C2 beacon patterns and flag connections initiated by sideloaded or unsigned DLLs.