A new cybercriminal campaign is exploiting the credibility of ChatGPT to lure users into a multi-layered attack that ends with the installation of remote access malware. Specialized versions of ChatGPT, promoted through Google sponsored results, direct unsuspecting users to malicious websites that use “ClickFix” attacks to install the malware.
The perpetrator exploits a legitimate feature of the AI platform, custom GPTs that allow users to create a version of ChatGPT tailored to a specific task, combining instructions, additional knowledge, and skills.
The campaign was spotted by Huntress, which says it has investigated at least 40 incidents linked to the infrastructure. The use of a custom GPT as the starting point of the attack adds a new layer of social engineering to a technique already widely used by cybercriminals.
See also: MCP Python SDK: Stealing OAuth credentials from malicious servers
The bait is hidden inside a GPT
Attackers exploited the ability to create customized versions of ChatGPT, designed for specific tasks. One of the malicious GPTs was named “Plus 5.6” and was used as a waypoint to guide victims.
The user arriving at GPT via Google was directed to a site backup, which was hosted on Google Sites. The choice of legitimate services and domains at different stages of the attack is not accidental, as it can make the chain appear more trustworthy to an unsuspecting visitor.
The page then displayed a fake Cloudflare verification, but instead of completing any real verification process, the victim was prompted to run a PowerShell command.

ClickFix turns the user into a "doer"
This is where the essence of the ClickFix. Instead of the malware being installed solely through a traditional exploit, the user is tricked into executing a command themselves.
This approach is particularly effective because the action is presented as a necessary step to resolve a supposed technical issue or complete a security check. In reality, the command triggers the next phase of the infection.
Huntress has previously documented similar attacks using deceptive ChatGPT conversations. However, leveraging custom GPTs is a different approach, as the malicious content is hosted within a function directly related to the official platform.
From PowerShell to RAT
Once the user executes the command, a multi-stage process begins. PowerShell installs a malicious MSI, which then uses a legitimately signed application in conjunction with a modified DLL to load the final payload.
The result is the installation of a Remote Access Trojan (RAT) . This malware can provide attackers with remote desktop access , audio and video recording capabilities via the camera, file search, and system information collection
See also: RatHat Android Malware Console uses Gemini to locate victims
At the same time, it can be used to install additional malicious payloads, turning an initial deception into a broader computer breach.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Persistence mechanisms in the Windows Registry
The perpetrators have taken steps to ensure that the malware remains active even after a system reboot. Specifically, a new Run key is created in the Windows Registry, while a scheduled task.
Both mechanisms use the name "Canon Configuration Reader", which can help hide malicious activity among legitimate system components.
The campaign also saw changes along the way. The first custom GPT variant was removed by OpenAI by September 25th, but on September 27th, Huntress detected a second GPT connected to the same infrastructure.
Custom encrypted file hides payload
One of the most interesting technical elements of the attack is the way the attackers hide part of their infrastructure. According to Huntress, they created a custom encrypted file system, which contains both the persistence script and the RAT.
The structure resembles a makeshift encrypted archive, with a header, an index of 1,128 entries , and the file data arranged sequentially. This approach makes simple file analysis difficult and suggests that the attack is designed to bypass traditional detection mechanisms.
See also: Hackers use NeedyMantis to maintain long-term access to compromised networks
What users should watch out for
For users, the most important takeaway is that no Cloudflare audit or similar verification process should require running random PowerShell commands. Commands copied from web pages and executed manually are a major red flag.

Huntress also highlights specific areas that security teams can look for, including unusual execution of msiexec.exe via PowerShell, launching signed applications from unexpected locations, and suspicious Registry values and scheduled tasks that reappear after being deleted.
This particular campaign highlights a broader problem: the trustworthiness of popular AI platforms can be used as part of a social engineering attack. The fact that a link or instruction appears within the ecosystem of a well-known service does not in itself mean that it is safe. Therefore, vigilance remains critical, especially when the user is asked to execute commands on their operating system.
source: www.bleepingcomputer.com
