Attackers have found a new way to abuse one of ChatGPT's own features: Custom GPTs, the no-code, shareable mini-assistants anyone can publish on OpenAI's platform. A campaign tracked by security researchers turns a fake "ChatGPT Plus 5.6" Custom GPT into the opening move of a multi-stage infection chain that ends with a full remote access trojan (RAT) on the victim's machine.
What happened
The lure starts in search results. Sponsored ads for common terms like "chatgpt" point to attacker-published Custom GPTs branded as a premium upgrade. Anyone who engages with the fake assistant is told the official subscription page has "limited availability" and is steered toward a "backup" page hosted on Google Sites instead — a trusted domain that helps the link slip past filters and instincts alike.
That backup page runs the now-familiar ClickFix playbook: a fake Cloudflare "verify you're human" check that walks the visitor through copying a command and pasting it into the Windows Run dialog themselves. The command downloads an MSI installer that abuses a legitimately signed Canon utility to sideload a malicious DLL. That DLL loads a second, unsigned DLL, which extracts an encrypted loader hidden inside an ordinary-looking WAV audio file. Before it deploys the final payload, the loader strips out built-in antivirus hooks and checks for signs of a virtual machine to avoid running inside a sandbox — then installs the RAT.
The resulting backdoor is broad-spectrum: it profiles installed security software, opens hidden remote desktop sessions, streams the screen, and can reach into the camera, microphone, and system audio. It searches file contents across the host, can launch any of 17 supported browsers, and drops or runs further executables, DLLs, and scripts on command. To reach its operators, it resolves command-and-control addresses via DNS-over-HTTPS through mainstream resolvers, a trick that keeps the traffic out of ordinary local DNS logs.
Why it matters
This isn't an isolated trick. It lands alongside a cluster of ClickFix-style campaigns seen in the same window: fake Google Sites pages impersonating OpenAI Codex and Anthropic's Claude, a compromised site using blockchain-hosted ("EtherHiding") scripts to serve a bogus CAPTCHA that drops a stealer and a reverse proxy, and malvertising chains staged on bulletproof hosting that deliver trojanized installers. One cluster has been linked to attacks on Ukrainian government systems. The common thread is social engineering that borrows credibility from platforms people already trust — AI assistants, CAPTCHAs, search ads — to get a victim to do the actual work of infecting their own machine.
What to do
- Treat any prompt that asks you to copy a command and paste it into "Run" or a terminal as a red flag, regardless of how official the surrounding page looks — this is the core of every ClickFix variant.
- Only manage ChatGPT (or any SaaS) subscriptions from the official app or account settings, never from a link surfaced inside a chat response or a sponsored search ad.
- Block or scrutinize execution of PowerShell/mshta spawned from browser processes, and alert on Run-dialog command execution where feasible.
- Monitor for DLL sideloading against known-signed utilities (including from vendors like Canon) and for unexpected DNS-over-HTTPS traffic from endpoints.
- Brief staff on the ClickFix pattern specifically — it defeats most email and web filtering because the malicious action is performed manually by the user.
