DKDKCISSPSearch
Cyber AttacksDEVELOPING

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

DKCISSP News DeskThe Hacker News30 Sept 2026, 9:22 pm
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

The two Custom GPT links are listed below - Users who end up interacting with the Custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain." To nudge unsuspecting users into opting for the latter option, the notice also displays the message: "We recommend using the backup domain if you need immediate access." Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command.

Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.

Prior campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs).

Custom GPTs refer to a personalized version of ChatGPT that, as the name implies, allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding.

At least 40 victims were impacted by the ClickFix attack, with two intrusions confirmed to have originated from the Custom GPT lure.

The Custom GPT was set up to respond to any prompt with a message saying the primary ChatGPT domain was experiencing availability issues and that the user could visit a backup domain to continue using the service, which led victims to a malicious website hosted on Google Sites.

Huntress found that victims were brought to the Custom GPT called Plus 5.6 through a Google Ad that displayed its link at the top of search results for “chatgpt.” This link brought users to a conversation with the Custom GPT hosted on the real ChatGPT website.

The RAT malware has been consistently found to drop a legitimately signed binary ("GOMCam2024.exe") that launches Google Chrome with a throwaway browser profile located in the "%TEMP%" directory.

This version led to the same RAT payload but with some differences in the attack chain; for example, the EXE used for DLL sideloading was changed from the Canon executable to Stardock’s DeElevate64.exe with a modified version of Stardock’s DeElevator64.dll replacing ceiinfolog.dll.

What happened

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

The two Custom GPT links are listed below - Users who end up interacting with the Custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain." To nudge unsuspecting users into opting for the latter option, the notice also displays the message: "We recommend using the backup domain if you need immediate access." Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command.

What changed

Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.

Prior campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs).

Who is affected

Custom GPTs refer to a personalized version of ChatGPT that, as the name implies, allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding.

At least 40 victims were impacted by the ClickFix attack, with two intrusions confirmed to have originated from the Custom GPT lure.

Why it matters

The Custom GPT was set up to respond to any prompt with a message saying the primary ChatGPT domain was experiencing availability issues and that the user could visit a backup domain to continue using the service, which led victims to a malicious website hosted on Google Sites.

Huntress found that victims were brought to the Custom GPT called Plus 5.6 through a Google Ad that displayed its link at the top of search results for “chatgpt.” This link brought users to a conversation with the Custom GPT hosted on the real ChatGPT website.

Technical details

The RAT malware has been consistently found to drop a legitimately signed binary ("GOMCam2024.exe") that launches Google Chrome with a throwaway browser profile located in the "%TEMP%" directory.

This version led to the same RAT payload but with some differences in the attack chain; for example, the EXE used for DLL sideloading was changed from the Canon executable to Stardock’s DeElevate64.exe with a modified version of Stardock’s DeElevator64.dll replacing ceiinfolog.dll.

Executing this command set off an eight-stage attack chain that culminated in the execution of the RAT malware.

Response

To detect this attack, Huntress recommends focusing on process activity, as most of the attack chain runs in memory.

In the final stage, the loader shellcode proceeds to unpack the trojan and a persistence script from an encrypted file system ("monitor.raw"), but not before bypassing AMSI, unhooking "ntdll.dll" to sidestep user-mode monitoring by security programs, and running anti-virtual machine checks by checking CPU vendor strings against various VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services.

What security teams should do

The DLL, per Huntress, is the real Canon DLL that's been altered to load a second, unsigned DLL ("rdCore.dll"), which later extracts an encrypted loader from a .WAV audio file ("Common.Integrator.Preview.wav").

Attribution

The Hacker News: Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

SC Media: Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.

What to watch next

Watch for updated vendor guidance and fixed-version details.

MORE IN CYBER ATTACKS

More cybersecurity reporting

RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model - Infosecurity MagazineInfosecurity Magazine · 29 Sept 2026, 8:00 pmMicrosoft Warns NeedyMantis Malware Enables Persistent Network AccessInfosecurity Magazine · 29 Sept 2026, 7:00 pmMicrosoft Warns NeedyMantis Malware Enables Persistent Network AccessInfosecurity Magazine · 29 Sept 2026, 7:00 pmBitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseThe Hacker News · 26 Sept 2026, 1:39 pm