Threat actors are abusing ChatGPT’s Custom GPT feature to funnel victims into a ClickFix attack that ends with a full-featured remote access trojan (RAT), according to new research from Huntress.
The attackers created a Custom GPT titled “Plus 5.6”, designed to pass as a genuine ChatGPT model. Because Custom GPTs are hosted on chatgpt.com, the lure sits on OpenAI’s legitimate domain. In some incidents, victims reached it through a sponsored Google result for “chatgpt”. Whatever the user types, the GPT replies with a fake “Service Availability Notice” directing them to a “backup domain” hosted on Google Sites.
That page poses as a Cloudflare CAPTCHA and instructs the victim to paste a command into their terminal. The PowerShell that runs references its server as a decimal-encoded IP address, a trick that slips past rules looking for dotted IPs, and pulls down a heavily obfuscated script that silently installs a malicious MSI.
Huntress researchers counted eight hops between the ClickFix command and the final payload. The MSI sideloads a patched Canon logging DLL through a legitimately signed Canon CaptureOnTouch executable. That DLL loads a helper that extracts the loader from a WAV audio file, where a section of real audio has been overwritten with encrypted shellcode. The loader includes an AMSI bypass, ntdll unhooking, and anti-VM checks, then unpacks the RAT from “monitor.raw”, a bespoke encrypted archive containing 806 files and a persistence script written in the malware’s own scripting language.
The RAT supports remote desktop sessions, webcam, microphone, and system audio capture, a file manager with content search across the host, and the ability to drop follow-on payloads in formats ranging from EXE and DLL to PowerShell and ZIP. It locates its command-and-control server via DNS-over-HTTPS through Cloudflare, Google, and Quad9, keeping lookups out of local DNS logs.
Persistence is handled by a Run key and a scheduled task, both named “Canon Configuration Reader”, which the implant recreates within minutes if either is removed. In at least one incident, Microsoft Defender quarantined the MSI after it had already run, and the persistence mechanisms continued the chain regardless.
The Huntress SOC has responded to at least 40 incidents tied to the Google Sites domain, two of which were confirmed to originate from a Custom GPT. OpenAI removed the original GPT on 25 September after Huntress reported it, but a replacement surfaced on 27 September alongside a second version of the chain. Version two swaps in a signed Stardock binary, hides the loader inside a genuine Microsoft NuGet package, obfuscates its stager freshly on every request and strips Mark-of-the-Web from the MSI. The RAT itself is byte-for-byte identical.
Huntress recommends defenders focus on behaviour rather than file names, since the operators appear to be rotating signed hosts. Signals include PowerShell launching msiexec on a GUID-named MSI in %TEMP%, a signed application started by msiexec from a fake product folder under %LOCALAPPDATA%\Programs\, and a Run value and scheduled task that share a name and reappear when deleted. When cleaning up, the process should be killed before removing either persistence mechanism.
Full technical analysis and indicators of compromise are available on the Huntress blog: https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat





