Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Abuse of ChatGPT Custom GPTs: A New Vector for Malicious Actors to Deliver RAT via ClickFix Lures


Attackers are leveraging the custom GPT feature of ChatGPT to deliver remote access trojans (RATs) via ClickFix lures, highlighting the evolving nature of cyber threats and the need for continuous vigilance and enhancement of security measures to prevent such attacks.

  • Threat actors are using ChatGPT's Custom GPT feature to deliver RAT via ClickFix lures, targeting unsuspecting victims.
  • Custom GPTs are being used to create convincing product offerings that direct victims to malicious sites.
  • The attack uses a Google Sites link to trick victims into downloading and executing a malicious MSI installer.
  • The MSI installer initiates a DLL sideloading chain to load shellcode, which launches a persistence script and RAT payload.
  • The RAT supports various features, including document installed antivirus, Microsoft Defender status, and system profile.
  • Threat actors are using AI to accelerate reconnaissance, compromise identities, and escalate access.
  • Security teams must develop strategies to fight back with runtime identity controls.



  • Threat Intelligence professionals and cybersecurity experts are on high alert as they have discovered a novel method by which attackers are leveraging the custom GPT (Generative Pre-trained Transformer) feature of ChatGPT, a popular artificial intelligence (AI) platform, to deliver remote access trojans (RATs) via ClickFix lures. According to recent observations made by the cybersecurity firm, Huntress, malicious actors have begun utilizing the custom GPT feature to create convincing product offerings that direct unsuspecting victims to malicious sites that employ ClickFix lures.

    In this context, custom GPT refers to a personalized version of ChatGPT that allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. These custom GPTs are hosted on the legitimate ChatGPT website with the Custom GPT name at the top. The malicious actors exploit this feature by creating custom GPTs that respond to user prompts with a message that includes a Google Sites link. When a victim interacts with the malicious custom GPT, they are redirected to a ClickFix-style attack, which ultimately leads to the download and execution of a malicious MSI installer.

    The MSI installer then initiates a DLL sideloading chain responsible for loading shellcode, which is used to launch a persistence script and a RAT payload. It is worth noting that the starting point of the attack is a sponsored result for searches like "chatgpt" on Google, with two custom GPT links listed below - chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6 and chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6.

    Victims who interact with the custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain." To nudge unsuspecting users into opting for the latter option, the notice also displays the message: "We recommend using the backup domain if you need immediate access."

    Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command. The PowerShell command is used to deploy an MSI installer ("ISOSimple.msi"), which abuses a legitimate Canon-signed binary ("COTFileReadApp.exe") to sideload a rogue DLL ("ceiinfolog.dll").

    The DLL, per Huntress, is the real Canon DLL that's been altered to load a second, unsigned DLL ("rdCore.dll"), which subsequently extracts an encrypted loader from a .WAV audio file ("Common.Integrator.Preview.wav"). While this is not the first time threat actors have smuggled their payload within audio and video file formats, WAV-hidden payloads have been previously observed in connection with Octowave Loader campaigns.

    In the final stage, the loader shellcode proceeds to unpack the trojan and a persistence script from an encrypted file system ("monitor.raw"), but not before bypassing AMSI, unhooking "ntdll.dll" to sidestep user-mode monitoring by security programs, and running anti-virtual machine checks by checking CPU vendor strings against various VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services.

    The trojan supports a wide range of features, including documents installed antivirus, Microsoft Defender status, and system profile; runs remote desktop sessions and screen "broadcasts"; captures the endpoint's camera input, the microphone, and system audio; recognizes 17 web browsers and can launch the default one; searches file contents across the system using a built-in file manager component; drops and runs secondary payloads (i.e., .EXE, .DLL, and .MSI) and scripts (i.e., PowerShell, batch, VBScript, and JavaScript); and employs a wide range of features that make it highly adaptable to different attack scenarios.

    According to Huntress, the starting point of the attack is a sponsored result for searches like "chatgpt" on Google, with the two custom GPT links listed below. The threat actors are likely to continue abusing this feature to deliver RAT via ClickFix lures, making it essential for cybersecurity professionals to remain vigilant and enhance their security measures to prevent such attacks.

    In related news, the cybersecurity firm, GuidePoint Security, has reported that the RAT malware has been consistently found to drop a legitimately signed binary ("GOMCam2024.exe") that launches Google Chrome with a throwaway browser profile located in the "%TEMP%" directory. The firm also stated that the RAT malware has been consistently found to use DNS-over-HTTPS through Cloudflare, Google, and Quad9 servers to find its C2 server, which is suspected to be hidden deep inside the code in an encrypted form or retrieved at runtime.

    Threat actors are continuing to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT's Custom GPT feature or through Google Sites for hosting a ClickFix attack. The findings coincide with the discovery of multiple ClickFix-oriented campaigns in the wild, which are using phishing websites hosted on Google Sites that mimic OpenAI Codex and Anthropic Claude to establish trust and serve a fake installation prompt, which uses ClickFix to distribute and execute stealer malware directly in memory.

    These campaigns have been targeting Ukrainian government systems and are attributed to a Russia-aligned activity cluster that's tracked as UAT-10820. In another variant, malicious actors are using malvertising, phishing emails, and a compromised retail website to direct users to a fake Cloudflare interstitial page staged on a bulletproof hosting provider (AS202412, registered to Seychelles-based OMEGATECH LTD) to deliver malicious payloads, including a trojanized installer that drops an infostealer, a Node.js implant, and a batch script that establishes persistence through a Windows Active Setup registry key.

    Overall, the abuse of ChatGPT Custom GPTs by malicious actors to deliver RAT via ClickFix lures highlights the evolving nature of cyber threats and the need for continuous vigilance and enhancement of security measures to prevent such attacks. Threat actors are using AI to accelerate reconnaissance, compromise identities, and escalate access, and security teams must develop strategies to fight back with runtime identity controls.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Abuse-of-ChatGPT-Custom-GPTs-A-New-Vector-for-Malicious-Actors-to-Deliver-RAT-via-ClickFix-Lures-ehn.shtml

  • https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html


  • Published: Wed Sep 30 11:59:54 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us