Malicious ChatGPT Custom GPT pushes RAT via ClickFix

Malicious ChatGPT Custom GPT pushes RAT via ClickFix

Attackers are buying sponsored Google search results to steer people toward a malicious ChatGPT Custom GPT called "Plus 5.6". The GPT sends visitors to a fake Cloudflare CAPTCHA page, which tricks them into installing a remote access trojan (RAT), according to Huntress.

Custom GPTs are tailored versions of ChatGPT that anyone can build with a feature OpenAI offers, and they are hosted on the legitimate chatgpt.com domain. In this campaign, that hosting gave the lure a trusted address.

"The campaign has impacted dozens of users: the Huntress SOC has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance," the researchers said.

From a search ad to a Terminal command

Huntress spotted the campaign in late September. People who searched Google for "chatgpt" saw sponsored results that linked to the attacker's Custom GPT.

When a visitor tried to use it, the GPT said the service was unavailable. It then pointed them to a "Backup Domain", which was a page hosted on Google Sites.

"This Google Sites page presents as a CloudFlare CAPTCHA check and delivers a ClickFix attack, telling users to copy-and-paste a command into their Terminal," the researchers explained.

ClickFix is a social engineering technique in which a fake error message or verification step convinces the victim to run a malicious command themselves. The method has become common, and Guy Fawkes News recently covered a placeholder domain now serving ClickFix lures.

Running the command started an infection chain that ended with a full-featured RAT. The malware was sideloaded through legitimately signed Canon executables, and in a later wave through signed Stardock executables. Abusing signed files from known vendors helps malicious code blend in with normal activity.

Taken down, then back again

OpenAI removed the first malicious Custom GPT after Huntress observed and reported it. The attackers soon published a new one and promoted it to Google users in the same way. The infection chain changed slightly, but the goal and the RAT were the same.

The second Custom GPT is still online, but it no longer points to the ClickFix page, according to Help Net Security. Huntress says the attackers are already working on a new installer.

"These campaigns often stay live for just hours or days before the provider takes the content down, but even in that short span, they can draw considerable attention," the researchers noted.

How to defend against it

For individual users the rule is simple. No legitimate website, CAPTCHA or "fix" will ask you to copy text and paste it into the Run dialog, Terminal, PowerShell or a command prompt. A page that asks for this is an attack.

Users should also be careful with sponsored search results and should not trust a page only because it is hosted on a well-known domain.

Organizations should use layered defenses. Training can reduce the number of employees who fall for ClickFix. Technical controls can make the instructions harder to follow, for example by restricting the Win+R Run dialog for standard users and locking down PowerShell. Where those controls cannot be applied, security teams need to be able to detect the attack.

Our Take

This campaign combines three trusted brands in one chain: Google's ad platform, OpenAI's chatgpt.com and Google Sites. Each step looks legitimate on its own, which suggests that domain reputation is becoming a weak signal for users and for some filtering tools.

It also shows how AI platforms are turning into infrastructure for attackers, not only targets. We have seen AI agents misused in campaigns such as the Carbonato malware, and user-built GPTs now appear as a delivery surface as well.

The quick return after the first takedown indicates that removal alone may not stop determined operators. It is worth watching whether the promised new installer appears, and whether ad networks and AI providers tighten checks on sponsored links and public Custom GPTs.