Cybersecurity

Cybercriminals Exploit Custom GPTs to Execute ClickFix Attacks and Deploy Remote-Access Malware

A malicious campaign exploited custom versions of ChatGPT to direct users to fake pages asking them to run PowerShell commands, leading to the deployment of a remote-access Trojan. Huntress observed at least 40 connections to the malicious page, confirming two infections linked to a custom GPT.

2026-09-29
3 min read
83 views
certi.news Editorial Team
Cybercriminals Exploit Custom GPTs to Execute ClickFix Attacks and Deploy Remote-Access Malware

Attackers exploited the custom GPTs feature in ChatGPT to direct users to malicious websites that execute ClickFix attacks and deploy remote-access malware (RAT), according to an investigation by Huntress. The malicious models appeared in paid Google Search results, giving the campaign an opportunity to reach users searching for specialized tools or assistants.

Custom GPTs allow the creation of ChatGPT versions that combine additional instructions, knowledge, and capabilities, and they can also be published for others to use. The attackers exploited this functionality to create a model named Plus 5.6, which directed users to a purported backup site hosted on Google Sites.

Infection Chain

The fake page displayed a bogus Cloudflare check and then asked the visitor to run a PowerShell command. Executing the command installed a malicious MSI file, which invoked a legitimate digitally signed application alongside a modified DLL to load the malware.

Hosting the malicious instructions on the ChatGPT.com domain gave the campaign an additional degree of credibility, which could increase the likelihood that a victim would follow the instructions. The resulting RAT provides capabilities for remote desktop access, capturing audio and images from the camera, searching for files, collecting host information, and executing additional payloads.

What Changed in the Approach?

Huntress had previously observed ClickFix attacks associated with deceptive ChatGPT conversations, but the use of custom GPTs represents a new approach in this campaign. To maintain persistence, the malware creates a Run value in the Windows Registry and a scheduled task, both named Canon Configuration Reader.

Huntress said it investigated at least 40 incidents that connected to the Google Sites page, but confirmed that only two were associated with a custom GPT version. OpenAI removed the first model by September 25, but on September 27, researchers found a second model linked to the campaign, which was still active when the report was published.

The newer versions used an application digitally signed by Stardock instead of an application signed by Canon, with changes to how the loader was concealed and delivered, while the final payload remained the same. The attackers also hid the persistence script and the RAT inside a custom encrypted file system that included a directory tree and an index containing 1,128 files and folders.

Indicators Defenders Can Monitor

  • PowerShell launching msiexec.exe to silently install an MSI from a temporary folder.
  • A digitally signed application starting from an unusual path under %LOCALAPPDATA%\Programs\.
  • A Registry value and scheduled task with the same name reappearing after they are deleted.
  • Monitoring process activity, because large parts of the infection chain operate in memory or use files that appear legitimate.

Why Does This Matter?

The campaign shows that trust in a legitimate domain or a digital signature alone is not sufficient to determine whether instructions or an application are safe. The practical danger does not lie in the custom GPT itself, but in using it as a trusted interface to direct the victim to execute local commands. The exact number of victims and the scope of the spread beyond the cases observed by Huntress remain unresolved in the available material.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news