ClickFix Operators Deploy Two Custom GPTs to Deliver RAT via Canon and Stardock Sideloading
Threat actors used two Custom GPTs to serve ClickFix lures that infected at least 40 systems with a RAT through signed binary abuse. The campaign adapted loaders after each OpenAI takedown and relied on Google sponsored results for distribution. This marks an operational shift toward AI platform abuse for initial access with minimal attacker infrastructure.
Huntress traced the campaign to two Custom GPT instances hosted on ChatGPT.com. Victims searching for ChatGPT encountered sponsored results pointing to the GPTs, which responded with Google Sites links. These pages delivered a Cloudflare CAPTCHA followed by a PowerShell command fetching an MSI that abused signed binaries for DLL sideloading and established persistence via registry keys and scheduled tasks. The chain progressed through heavily obfuscated loaders stored as audio files or NuGet packages before dropping a RAT using DNS-over-HTTPS to Cloudflare, Google, and Quad9 resolvers.
OpenAI removed the first GPT on 25 September and a second on or after 27 September. The operators adapted quickly, switching from a Canon-signed executable to a patched Stardock DLL while retaining the same final payload. This rapid iteration after takedown indicates low operational friction and continued access to paid advertising inventory.
The technique exploits the visibility of sponsored search results and the trust signal of ChatGPT.com domains. It also demonstrates how commodity social-engineering frameworks like ClickFix are being augmented with AI-hosted lures that require no custom infrastructure beyond the initial GPT configuration.
OpenAI's moderation remains reactive. Similar abuse vectors will persist until sponsored result vetting and GPT creation controls address impersonation of software updates and limited-availability notices.
Huntress: At least one additional malicious Custom GPT will be observed in the next 10 days before OpenAI rate-limits GPT creation tied to new accounts.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/)
- [2]Supporting Source(https://www.huntress.com/blog/clickfix-gpt-campaign)