Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Threat actors exploited ChatGPT's Custom GPT feature to impersonate legitimate ChatGPT models, directing victims through sponsored Google ads to malicious Custom GPTs titled 'Plus 5.6'. These instances served fake service availability notices, redirecting users to Google Sites pages hosting ClickFix lures disguised as CloudFlare CAPTCHA checks. Victims were tricked into executing PowerShell commands that downloaded malicious MSI installers. The attack chain employed DLL sideloading through legitimate Canon-signed and later Stardock-signed executables, establishing dual persistence mechanisms via registry Run keys and scheduled tasks. The multi-stage infection involved obfuscated scripts, encrypted payloads hidden in WAV files and NuGet packages, and ultimately deployed a feature-rich remote access trojan with capabilities including remote desktop, browser hijacking, credential theft, and follow-on payload delivery. Huntress investigated approximately 40 incidents linked to this campaign, with confirmed Cus...
Pulse ID: 6ac12c993806593609d1c30c
Pulse Link: https://otx.alienvault.com/pulse/6ac12c993806593609d1c30c
Pulse Author: AlienVault
Created: 2026-10-03 16:26:01
Be advised, this data is unverified and should be considered preliminary. Always do further verification.

