Malicious Custom ChatGPT GPTs Push ClickFix Attacks and RAT Malware
Malicious variants of OpenAI’s ChatGPT promoted in Google sponsored search results are directing unsuspecting users to websites that use ClickFix attacks to deliver remote access Trojan (RAT) malware.
Threat actors are abusing legitimate AI platform features that let users create tailored versions of ChatGPT for specific tasks using custom instructions, additional knowledge, and specialized skills.
OpenAI can host these custom GPTs and publish them for other users to install and use. The company plans to retire custom GPTs on December 11.
Malicious “Plus 5.6” GPT directs users to a fake Cloudflare check
The campaign was identified by managed detection and response (MDR) company Huntress, whose researchers say it affected dozens of users.
The attackers named the malicious GPT model “Plus 5.6” and configured it to direct users to a backup website allegedly hosted on Google Sites.

Source: Huntress
The page displays a fake Cloudflare verification check that instructs visitors to run PowerShell commands. Following those instructions starts the malware infection chain.
Huntress researchers have observed similar attacks in the past. This campaign uses a deceptive ChatGPT conversation to launch the ClickFix ruse and compromise the target, but abusing a custom GPT represents a new approach.
In both attacks, the malicious instructions are hosted on the legitimate ChatGPT.com domain. This lends credibility to the operation and increases the likelihood that victims will follow the instructions.
PowerShell command installs a remote access Trojan
When executed locally, the provided PowerShell command installs a malicious MSI package. The MSI launches a legitimate signed application alongside a modified DLL that loads the malware.
The payload used in this campaign is a remote access Trojan (RAT) capable of:
- Providing remote desktop access
- Capturing audio and camera feeds
- Searching files
- Performing host reconnaissance
- Executing additional payloads
To establish persistence, the malware creates a new Windows Registry Run key and a scheduled task. Both are named “Canon Configuration Reader.”

Source: Huntress
Campaign remains active after a second malicious GPT is found
Huntress said it investigated at least 40 incidents involving connections to Google Sites pages, but confirmed that only two involved custom GPT variants.
OpenAI removed the first malicious GPT by September 25. Two days later, on September 27, researchers discovered a second GPT linked to the same campaign. The campaign was still active at the time of publication.
A recent version of the attack switched from a Canon-signed hosted application to a Stardock-signed hosted application. The change altered how the loader was concealed and delivered, although the payload remained the same.

Source: Huntress
Custom encrypted archive hides persistence script and RAT
Huntress highlighted the sixth phase of the multistep attack chain, during which the attackers built a custom encrypted file system to hide the persistence script and RAT.
“Instead of one encrypted blob, it’s a custom archive with its own folder tree, essentially a homemade encrypted zip file,” researchers say.
“It starts with a small header, followed by an index of 1,128 entries—one for each file or folder, each recording its parent, its size, and a key for each file—and then the contents of the files are packed back to back.”
Detection opportunities for defenders
Most infection chains run in memory or rely on files that appear harmless, Huntress said. This enables defenders to develop detections based on suspicious process activity.
The researchers identified several detection opportunities, including PowerShell contacting msiexec.exe and silently launching an MSI installer from a temporary folder.
Additional indicators of compromise include:
- Signed applications launching from unusual folders under
%LOCALAPPDATA%\Programs\ - Matching Registry Run values and scheduled tasks
- Run values and scheduled tasks reappearing after deletion
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



