Fake ChatGPT Custom GPTs Spread RAT via ClickFix Lures
AI-generated image

Fake ChatGPT Custom GPTs Spread RAT via ClickFix Lures

Attackers are disguising malicious ChatGPT Custom GPTs as product pages, using fake CAPTCHA checks to trick users into running commands that install a remote ac…

Security researchers at Huntress have uncovered a campaign in which attackers are abusing ChatGPT Custom GPTs, the personalized versions of the popular AI assistant, to disguise malicious activity as legitimate product offerings. The attackers direct victims to external sites that use a technique known as ClickFix to trick them into copying and running a malicious command, which ultimately installs a remote access trojan (RAT). Huntress observed the activity in late September 2026, noting that this is another instance of threat actors weaponizing features within trusted AI platforms. Previous campaigns have abused shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and RATs.

Custom GPTs are user-defined versions of ChatGPT that allow individuals to set custom instructions, upload reference files, and enable specific skills without any coding. They are hosted on the legitimate ChatGPT website, with the Custom GPT name displayed at the top. In the incidents Huntress observed, victims interacted with an attacker-created Custom GPT that had been programmed to respond to any prompt with a message containing a Google Sites link. That link led to a ClickFix-style attack, which resulted in the download and execution of a malicious MSI installer. No fewer than 40 users have been infected as part of this campaign.

The attack begins when users click on a sponsored search result for terms like 'chatgpt' on Google. Two Custom GPT links were identified: chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6 and chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6. Users who interact with the Custom GPT named 'Plus 5.6' are shown a 'Service Availability Notice' that tells them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to 'limited availability on the primary domain.' To encourage the backup option, the notice displays the message: 'We recommend using the backup domain if you need immediate access.' If the victim follows through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers the ClickFix attack, deceiving them into copying and executing a malicious PowerShell command. This command deploys an MSI installer named 'ISOSimple.msi', which abuses a legitimate Canon-signed binary called 'COTFileReadApp.exe' to sideload a rogue DLL named 'ceiinfolog.dll'. Huntress explains that the DLL is the real Canon DLL that has been altered to load a second, unsigned DLL called 'rdCore.dll', which then extracts an encrypted loader from a .WAV audio file named 'Common.Integrator.Preview.wav'. While smuggling payloads within audio and video file formats is not new, WAV-hidden payloads have previously been connected to Octowave Loader campaigns.

In the final stage, the loader shellcode unpacks the trojan and a persistence script from an encrypted file system called 'monitor.raw', but not before bypassing AMSI (Antimalware Scan Interface), unhooking 'ntdll.dll' to sidestep user-mode monitoring by security programs, and running anti-virtual machine checks by looking for CPU vendor strings associated with VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services. The trojan itself supports a wide range of features, including documenting installed antivirus and Microsoft Defender status, capturing system profile information, running remote desktop sessions and screen broadcasts, capturing camera input, microphone, and system audio, recognizing 17 web browsers and launching the default one, searching file contents across the system using a built-in file manager component, and dropping and running secondary payloads such as EXE, DLL, and MSI files, as well as PowerShell, batch, VBScript, and JavaScript scripts. To find its command-and-control (C2) server, which the malware authors call the 'Gate', the RAT uses DNS-over-HTTPS (DoH) through Cloudflare, Google, and Quad9 resolvers. Huntress notes that the lookups travel inside ordinary HTTPS traffic to well-known resolvers, so they never appear in local DNS logs. It is suspected that the server details are hidden deep inside the code in an encrypted form or retrieved at runtime. The RAT has also been consistently found to drop a legitimately signed binary named 'GOMCam2024.exe' that launches Google Chrome with a throwaway browser profile located in the '%TEMP%' directory.

The findings coincide with the discovery of multiple ClickFix-oriented campaigns in the wild. One campaign uses phishing websites hosted on Google Sites that mimic OpenAI Codex and Anthropic Claude to establish trust and serve a fake installation prompt, which uses ClickFix to distribute and execute stealer malware directly in memory. That stealer can fingerprint the host and contact an external domain to fetch next-stage payloads for data and cryptocurrency wallet theft. Another campaign involves a likely compromised website that uses EtherHiding to fetch JavaScript serving a ClearFake reCAPTCHA verification prompt, coercing victims into running a malicious command that opens a WebDAV path and retrieves a DLL. The DLL payload initiates a multi-stage process to drop Amatera Stealer, which siphons sensitive data and runs three secondary payloads: a NativeAOT loader, ZigCryptoStealer, and a Go reverse TCP proxy. Another build of the stealer has been found to install NetSupport Manager. Some of these attacks have targeted Ukrainian government systems and are attributed to a Russia-aligned activity cluster tracked as UAT-10820. A third campaign uses malvertising, phishing emails, and a compromised retail website to direct users to a fake Cloudflare interstitial page staged on a bulletproof hosting provider (AS202412, registered to Seychelles-based OMEGATECH LTD). This delivers malicious payloads, including a trojanized installer that drops an infostealer, a Node.js implant, and a batch script that establishes persistence through a Windows Active Setup registry key. A fourth ClickFix campaign, active since at least November 2025, uses a cluster of 31 compromised business websites to display a fake CAPTCHA lure that delivers a dropper. The dropper executes a PowerShell script to set up persistence and a C2 agent that uses EtherHiding by querying the Polygon blockchain to identify the C2 server, which it then uses to receive and execute arbitrary PowerShell commands. GuidePoint Security added that what began as a general-purpose remote-access backdoor has since been observed delivering a real-time banking trojan capable of intercepting login credentials and two-factor codes from major banks and cryptocurrency exchanges as victims type them.

For website owners and IT teams, the RAT's use of DNS-over-HTTPS to hide its command-and-control traffic illustrates why visibility into DNS queries is important. A secure, private DNS service like AEU DNS (https://aeu-dns.com) can help users avoid relying on public resolvers that offer less transparency, thou

How to Protect Yourself

  1. Be cautious with sponsored search results, especially for popular tools like ChatGPT, and type the official URL directly into your browser instead of clicking ads.
  2. Never copy and paste commands from websites, especially PowerShell commands, even if a page looks like a security or CAPTCHA check.
  3. If a ChatGPT Custom GPT asks you to visit an external site for a 'backup domain' or to 'upgrade your subscription,' treat it as suspicious and close the tab.
  4. Keep your operating system and security software up to date, and run a full scan if you think you might have run something malicious.
  5. Enable multi-factor authentication on your important accounts to protect against credential theft if malware does infect your computer.

Terms Explained

  • Custom GPT A personalized version of ChatGPT that users can configure with specific instructions, files, and skills.
  • ClickFix A social engineering trick that gets people to copy and run a malicious command, often hidden inside a fake CAPTCHA or verification prompt.
  • RAT (Remote Access Trojan) A type of malware that lets an attacker take remote control of an infected computer.
  • DLL sideloading A technique where attackers place a malicious DLL file so that a legitimate program loads it instead of the real one.
  • DNS-over-HTTPS A way of sending DNS queries over an encrypted HTTPS connection, which can hide them from normal network monitoring.
  • AMSI (Antimalware Scan Interface) A Windows security feature that allows antivirus software to scan scripts and other content for malicious code.

Related AEU services