Executive Summary
On 28 September 2026, Huntress researchers reported threat actors exploiting ChatGPT Custom GPTs as a delivery mechanism for ClickFix lures and DLL-sideloaded malware, including a Remote Access Trojan (RAT). This campaign represents a novel abuse of legitimate AI platforms to socially engineer victims and bypass traditional security controls.
Key Takeaways
Key points provided by Huntress include:
- “Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate product offerings, then directing victims to a malicious “backup” site through a trusted ChatGPT-hosted interface. Huntress researchers found two Custom GPTs linked to the same campaign that were being used in this manner.
- The campaign uses a ClickFix lure to trick victims into running PowerShell, which downloads a malicious MSI and begins a multi-stage, obfuscated infection chain.
- The payload establishes resilient access through dual persistence and DLL sideloading, using a Canon-signed executable (and, in a later wave, a Stardock-signed one) to load malicious code. Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections.”
Technical Details
Huntress researchers identified the attack chain as involving Custom GPTs configured to serve ClickFix-style lures, ultimately leading to DLL-sideloaded malware execution. Huntress provided the following infection chain visual:
Mitigation Options
- Monitor AI platform usage: Apply content inspection and logging for interactions with AI tools that could deliver executable instructions or scripts.
- Block ClickFix-style lures: Educate users on fake CAPTCHA and error-prompt social engineering tactics.
- DLL Sideloading Controls: Enforce application whitelisting and monitor for unsigned or unexpected DLL loads.
- Restrict script execution: Apply PowerShell and script execution policies (e.g., Constrained Language Mode).
- Endpoint Detection: Ensure EDR solutions are tuned to detect RAT behavior such as C2 beaconing and process injection.