A new ClickFix attack abuses the real ChatGPT Web domain to infect victims with remote access Trojans (RATs).
That’s according to Huntress, which this week published its findings about a new campaign that involves malicious Custom GPTs. As the name suggests, these are customized versions of ChatGPT that users and organizations can create to serve various functions, like personal research assistants, HR knowledge bases for employees, customer-facing product support, and more.
According to Huntress’ Mark O’Halloran and Jonathan Semon, attackers created Custom GPTs to mimic real product offerings, then leveraged OpenAI’s trusted Web infrastructure to direct victims to a malicious site. Victims would then be served a ClickFix-style prompt that attempts to trick them into executing a PowerShell command, which then downloads an MSI file and kicks off the attacker’s multistage infection chain. Huntress found two such Custom GPTs being used in this manner.
Huntress said the campaign has affected dozens of users to date; the security firm’s security operations center (SOC) “has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance.”
A Complex ClickFix Attack Leading to a RAT
ClickFix has become an exceedingly popular social engineering technique in recent years. It typically involves a victim visiting an attacker-controlled website (often mimicking a legitimate service like Zoom), where the victim is told that there is a technical issue and they must copy and paste system commands — the “click” — to “fix” it. The technique works because it exploits trust in commercial software as well as human problem-solving tendencies.
This campaign is particularly deceptive because these Custom GPTs are made to look like actual ChatGPT instances. Visitors reach them through the official ChatGPT domain, and to many users, the name, “Plus 5.6,” might look like an official OpenAI release.
Once the victim types any prompt into this Custom GPT, the output warns the user that the service is unavailable; they can either upgrade their subscription or use the “backup” domain, which is a Google Sites link. That link goes to a fake Cloudflare landing page with a fake CAPTCHA, where the user ultimately gets a standard ClickFix prompt to kick off the infection chain.
The PowerShell command downloads an MSI file, which abuses a legitimate, Canon-signed application to sideload malicious DLLs. One of those DLLs extracts an encrypted loader hidden inside a WAV file, decrypts it, and executes it in memory. The loader then retrieves the RAT from a separate encrypted storage file. That loader unpacks the RAT. Another variant the researchers discovered uses a different loader carrier and a different signed application, but the general shape of the infection appears to be virtually identical.
The infection’s ultimate goal is to deploy a RAT, which threat actors often use to gain a durable foothold into an organization’s environment. While the exact attacker motivations are unclear, a RAT can form the basis for data theft, extortion-based attacks, espionage, and more.
Semon, who is principal security operations analyst at Huntress, tells Dark Reading that of the incidents the company has investigated, the most common next step taken against compromised victims has been the installation of more malware; the RAT pulled down additional payloads intended to steal browser data and map out the victim’s endpoint.
“Thankfully, our team updated detections fast enough that we got ahead of most of these chains and isolated the machines before the second round of tools landed,” he says.
Still, the RAT poses significant risks to organizations. “Left alone, though, this RAT is built to do three things: steal data, watch the people using the machine, and serve as a foothold into the rest of the network,” Semon says. “It can run hidden remote desktop sessions, turn on the camera and microphone, search every file on the machine, create its own user accounts, and pull in whatever the attacker wants next. On an unmonitored machine, you should assume all of that is on the table.”
Recalibrate Awareness Training Toward the ClickFix Vector
For the technical aspects of the attack, Huntress’ blog post includes indicators of compromise, but ClickFix attacks are particularly troublesome because they trick the user into initiating the compromise themselves.
And for this campaign in particular, perhaps the most dangerous aspect from a social engineering standpoint is that every domain used to gain a foothold in the victim’s environment is trusted, namely ChatGPT and Google. Semon says that because the trusted domain stopped being a useful signal, awareness training has to move from “check where it came from” to “check what it’s asking you to do.”
“In some of the incidents we investigated, people searched Google for ‘chatgpt,’ clicked a sponsored result, and landed on a real chatgpt.com page that passed for a new model, with only a small ‘community builder’ label as a hint,” he says. “The rule that holds up is simple: no website, chatbot, support page, or ‘verification tool’ has a legitimate reason to tell you to paste a command into PowerShell or any Terminal to verify who you are, no matter how polished it looks.”
Dark Reading has contacted OpenAI for comment.

No responses yet