Threat Actors Weaponize Custom GPTs to Deliver Malware
Key Takeaways Cyberattackers are leveraging ChatGPT’s Custom GPT feature to impersonate legitimate AI services. The campaign, dubbed “ClickFix,” tricks users into installing a...
Key Takeaways
- Cyberattackers are leveraging ChatGPT’s Custom GPT feature to impersonate legitimate AI services.
- The campaign, dubbed “ClickFix,” tricks users into installing a sophisticated remote access trojan (RAT).
- The attack chain involves malvertising, deceptive CAPTCHA prompts, obfuscated PowerShell scripts, malicious MSI packages, and DLL sideloading.
- The RAT grants attackers extensive control, including remote desktop access, camera/microphone capture, and further payload execution.
- Users should be highly suspicious of any website, especially AI services, that requests they execute PowerShell or terminal commands for verification.
Attackers Exploit Custom GPTs to Deliver Advanced RAT
Threat actors are actively misusing OpenAI’s Custom GPT functionality within ChatGPT to masquerade as official AI tools, subsequently luring unsuspecting users into downloading a powerful remote access trojan (RAT). This sophisticated campaign leverages a combination of social engineering and technical evasion techniques, turning trusted ChatGPT-hosted pages into the initial point of compromise.
Table Of Content
The ClickFix Campaign Unveiled
According to research published by Huntress, this operation, termed “ClickFix,” integrates several malicious components: malvertising, counterfeit verification prompts, heavily obfuscated PowerShell scripts, malicious MSI packages, and DLL sideloading. Huntress investigators tracked at least 40 incidents linked to the campaign’s Google Sites infrastructure, with two confirmed infections originating from malicious Custom GPTs.
The attack frequently commences when users search Google for “chatgpt” and click on sponsored results that redirect to a chatgpt.com domain. Attackers named their Custom GPT “Plus 5.6” to mimic an official model, despite the page identifying its creator as a “community builder.” Interacting with this deceptive GPT then triggers a “Service Availability Notice,” falsely claiming limited availability on the primary domain and directing the user to a supposed backup site.
This “backup site” is typically a Google Sites page meticulously designed to resemble a ChatGPT and Cloudflare CAPTCHA verification screen. Instead of performing legitimate verification, the ClickFix lure instructs victims to paste and execute a malicious PowerShell command. Microsoft defines ClickFix as a social engineering tactic where users are manipulated into running malicious commands themselves, often under the pretense of resolving minor errors or completing CAPTCHA checks.
Deep Dive into the Infection Chain
The malicious PowerShell command, once executed, downloads a highly obfuscated script into the Windows temporary directory. Huntress analysis revealed that the server address for this download was represented as the decimal value 1614733393, which Windows resolves to 96.62.224[.]81. This unusual format likely aims to bypass network filters that only scan for traditional dotted-decimal IP addresses.
After two layers of integer-based obfuscation are decoded, the script fetches “ISOSimple.msi.” This MSI package is then silently installed using msiexec and immediately deleted. The MSI disguises itself as “Advanced Printer Configuration Reader,” conceals its presence from the Programs and Features list, and installs itself within the %LOCALAPPDATA%Programs directory.
The core of the attack involves launching Canon’s legitimately signed “COTFileReadApp.exe.” This legitimate executable is then exploited to load a modified “ceiinfolog.dll” from the same directory, a classic DLL sideloading technique. This malicious DLL, in turn, pulls in “rdCore.dll,” extracts encrypted loader code hidden within “Common.Integrator.Preview.wav,” and executes it directly in memory.
The in-memory loader incorporates several advanced evasion techniques, including an AMSI bypass, ntdll unhooking, anti-virtual-machine checks, and in-memory .NET execution. Following these steps, it opens “monitor.raw,” a custom encrypted archive that contains the persistence mechanisms and the final RAT payload.
Persistence and RAT Capabilities
To maintain persistence, the malware establishes an HKCU Run value and a scheduled task, both named “Canon Configuration Reader.” These persistence mechanisms are designed to rebuild themselves automatically if removed.
The deployed RAT is highly capable, offering attackers comprehensive control over the compromised system. Its functionalities include remote desktop access, camera and microphone capture, file searching, browser launching, system reconnaissance, and the ability to execute additional payloads such as EXEs, DLLs, MSIs, PowerShell scripts, or other scripts. For command-and-control (C2) communications, the RAT resolves its infrastructure using DNS-over-HTTPS via Cloudflare, Google, and Quad9, further complicating detection.
Evolving Tactics and Mitigation
After OpenAI removed the initial malicious GPT by September 25, Huntress observed a new iteration emerge on September 27. While retaining the same RAT, the updated campaign swapped Canon’s executable for Stardock-signed “DeElevate64.exe.” Furthermore, the loader was moved into a Microsoft NuGet package named “Build.dat,” and the Mark-of-the-Web (MotW) was stripped before installation to evade security controls.
What You Should Do
- Exercise Extreme Caution with Shell Commands: Immediately close any CAPTCHA or AI service page that requests you open PowerShell, Terminal, or the Run dialog and paste a command. Legitimate verification processes never require direct shell execution.
- Prioritize Behavioral Detection: Defenders should focus on behavioral detection rather than relying solely on product names, as attackers frequently rotate signed host applications.
- Monitor for Suspicious Process Activity: Look for PowerShell spawning msiexec for GUID-named MSI files in the %TEMP% directory.
- Inspect Executable Paths: Watch for signed Canon or Stardock binaries launching from unexpected paths within %LOCALAPPDATA%Programs.
- Verify Persistence Mechanisms: Check for matching Run-key and scheduled-task names (“Canon Configuration Reader”) that appear suspicious or are not tied to legitimate software.
- Scrutinize DLLs: Be alert for unsigned or checksum-modified DLLs co-located with legitimate executables.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.