Attackers Abusing ChatGPT Custom GPTs to Deliver RAT via ClickFix

Executive Summary

On 28 September 2026, Huntress researchers reported threat actors exploiting ChatGPT Custom GPTs as a delivery mechanism for ClickFix lures and DLL-sideloaded malware, including a Remote Access Trojan (RAT). This campaign represents a novel abuse of legitimate AI platforms to socially engineer victims and bypass traditional security controls.

Key Takeaways

Key points provided by Huntress include:

  • “Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate product offerings, then directing victims to a malicious “backup” site through a trusted ChatGPT-hosted interface. Huntress researchers found two Custom GPTs linked to the same campaign that were being used in this manner.
  • The campaign uses a ClickFix lure to trick victims into running PowerShell, which downloads a malicious MSI and begins a multi-stage, obfuscated infection chain.
  • The payload establishes resilient access through dual persistence and DLL sideloading, using a Canon-signed executable (and, in a later wave, a Stardock-signed one) to load malicious code. Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections.”

Technical Details

Huntress researchers identified the attack chain as involving Custom GPTs configured to serve ClickFix-style lures, ultimately leading to DLL-sideloaded malware execution. Huntress provided the following infection chain visual:

Mitigation Options

  • Monitor AI platform usage: Apply content inspection and logging for interactions with AI tools that could deliver executable instructions or scripts.
  • Block ClickFix-style lures: Educate users on fake CAPTCHA and error-prompt social engineering tactics.
  • DLL Sideloading Controls: Enforce application whitelisting and monitor for unsigned or unexpected DLL loads.
  • Restrict script execution: Apply PowerShell and script execution policies (e.g., Constrained Language Mode).
  • Endpoint Detection: Ensure EDR solutions are tuned to detect RAT behavior such as C2 beaconing and process injection.

More Recent Blog Posts

Executive Summary Microsoft Security Research published in a report on 9 September 2026 tracking active cloud-based intrusions spanning multiple accounts in which unusual...

Executive Summary Arctic Wolf is tracking a widespread data theft and extortion threat cluster designated as PREY-0058, also known as Cordial Spider and...

Executive Summary A dark web marketplace is selling 153,000,000 American and Canadian driver’s licenses, reportedly siphoned from idscan[.]net, according to multiple social media...