International Cyber Expo International Cyber Expo
  • About Us
Tuesday, 29 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain

Huntress links at least 40 incidents to a campaign that hides malware inside a WAV file, a custom encrypted file system and signed Canon and Stardock binaries

by Guru Writer
September 29, 2026
in AI and Machine Learning, News
Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain
Share on FacebookShare on Twitter

Threat actors are abusing ChatGPT’s Custom GPT feature to funnel victims into a ClickFix attack that ends with a full-featured remote access trojan (RAT), according to new research from Huntress.

The attackers created a Custom GPT titled “Plus 5.6”, designed to pass as a genuine ChatGPT model. Because Custom GPTs are hosted on chatgpt.com, the lure sits on OpenAI’s legitimate domain. In some incidents, victims reached it through a sponsored Google result for “chatgpt”. Whatever the user types, the GPT replies with a fake “Service Availability Notice” directing them to a “backup domain” hosted on Google Sites.

That page poses as a Cloudflare CAPTCHA and instructs the victim to paste a command into their terminal. The PowerShell that runs references its server as a decimal-encoded IP address, a trick that slips past rules looking for dotted IPs, and pulls down a heavily obfuscated script that silently installs a malicious MSI.

Huntress researchers counted eight hops between the ClickFix command and the final payload. The MSI sideloads a patched Canon logging DLL through a legitimately signed Canon CaptureOnTouch executable. That DLL loads a helper that extracts the loader from a WAV audio file, where a section of real audio has been overwritten with encrypted shellcode. The loader includes an AMSI bypass, ntdll unhooking, and anti-VM checks, then unpacks the RAT from “monitor.raw”, a bespoke encrypted archive containing 806 files and a persistence script written in the malware’s own scripting language.

The RAT supports remote desktop sessions, webcam, microphone, and system audio capture, a file manager with content search across the host, and the ability to drop follow-on payloads in formats ranging from EXE and DLL to PowerShell and ZIP. It locates its command-and-control server via DNS-over-HTTPS through Cloudflare, Google, and Quad9, keeping lookups out of local DNS logs.

Persistence is handled by a Run key and a scheduled task, both named “Canon Configuration Reader”, which the implant recreates within minutes if either is removed. In at least one incident, Microsoft Defender quarantined the MSI after it had already run, and the persistence mechanisms continued the chain regardless.

The Huntress SOC has responded to at least 40 incidents tied to the Google Sites domain, two of which were confirmed to originate from a Custom GPT. OpenAI removed the original GPT on 25 September after Huntress reported it, but a replacement surfaced on 27 September alongside a second version of the chain. Version two swaps in a signed Stardock binary, hides the loader inside a genuine Microsoft NuGet package, obfuscates its stager freshly on every request and strips Mark-of-the-Web from the MSI. The RAT itself is byte-for-byte identical.

Huntress recommends defenders focus on behaviour rather than file names, since the operators appear to be rotating signed hosts. Signals include PowerShell launching msiexec on a GUID-named MSI in %TEMP%, a signed application started by msiexec from a fake product folder under %LOCALAPPDATA%\Programs\, and a Run value and scheduled task that share a name and reappear when deleted. When cleaning up, the process should be killed before removing either persistence mechanism.

Full technical analysis and indicators of compromise are available on the Huntress blog: https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat

ShareTweet
Previous Post

New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence

Next Post

Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk

Recent News

Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk

Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk

September 29, 2026
Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain

Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain

September 29, 2026
cyber threat intelligence

New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence

September 28, 2026
James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind

James Moore, CultureAI Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind

September 28, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol