research / malicious-custom-gpt-clickfix-rat
Malicious Custom GPTs turn chatgpt.com into a ClickFix RAT lure
Huntress traced malicious Custom GPTs on chatgpt.com that pushed users to a Google Sites ClickFix page ending in an eight-stage RAT, plus what to monitor.
Attackers are registering Custom GPTs on chatgpt.com, promoting them through paid Google search results, and programming them to steer visitors into a ClickFix trap that ends in a full remote access trojan. Huntress documented the campaign in late September after its security operations center responded to at least 40 incidents tied to the Google Sites domain behind it. If your controls and your awareness training both lean on "check the domain before you trust it," this campaign is built to defeat exactly that signal.
How the Custom GPT lure works
Custom GPTs are user-built versions of ChatGPT that live on chatgpt.com, with the builder's profile under the title. Huntress found two tied to this campaign, both titled "Plus 5.6", close enough to a model name that an unknowing visitor reads it as a new OpenAI release. The only honest marker on the page is a small "community builder" label.
Several victims arrived through a sponsored result while searching Google for "chatgpt". The landing URL carried the gad_source and gad_campaignid parameters Google appends to paid ad clicks, putting the attacker's link above the organic results. Type anything into the GPT and it replies with a "Service Availability Notice": limited availability on the primary domain, so either upgrade your subscription or continue through a backup domain. The backup is a Google Sites page styled as a Cloudflare CAPTCHA check, which hands out the standard ClickFix instruction to paste a PowerShell command into a terminal.
Huntress reported the first Custom GPT to OpenAI, which took it down on September 25. A replacement appeared on September 27 and was still active when the research was published. The same playbook has shown up in earlier AI platform abuse Huntress tracked: SEO-poisoned ChatGPT and Grok conversations that told Mac users to run commands deploying the AMOS stealer, and a malicious Claude Artifact impersonating a Claude Desktop download page before redirecting to SectopRAT.
Eight stages from a pasted command to the RAT
Most ClickFix chains run two or three hops. This one runs eight, and each stage exists to hide the next.
The pasted command pulls a script with irm from a host written as a decimal number, 1614733393, which Windows resolves to 96.62.224.81. Rules hunting dotted-quad addresses never match. The script that lands in %TEMP% is a single line of 27,581 characters, nearly all of it 3,036 negative integers that get shifted back into working code in memory and executed with [scriptblock]::Create, so the rebuilt script never touches disk. The download URL sits under a second integer-key layer.
The decoded script fetches an MSI over plain HTTP under a fresh GUID name and installs it silently. The package presents as "Advanced Printer Configuration Reader" from a publisher called Softplicity, sets ARPSYSTEMCOMPONENT=1 so it vanishes from Programs and Features, and launches as soon as installation finishes. In one incident Microsoft Defender quarantined the MSI as Trojan:Script/Wacatac.H!ml, after the persistence was already in place.
Of the installer's 177 files, eight do the work. A legitimate Canon-signed binary from CaptureOnTouch, COTFileReadApp.exe, acts as host process. It loads Canon's logging library by name from its own folder, and the ceiinfolog.dll beside it is the genuine Canon DLL with its signature stripped and one import added: rdCore.dll. Windows resolves import-table entries before the library's own code runs, so the malicious DLL arrives without any change to Canon's binary.
rdCore.dll then seeks to offset 0x24362 inside Common.Integrator.Preview.wav, reads 341,395 bytes, and decodes them with a rolling single-byte XOR where the algorithm itself is the key. The WAV has a valid RIFF header and real audio at the start, so tooling that types files by header passes it. The output is position-independent x64 shellcode with no readable strings: an AMSI bypass, a fresh copy of ntdll to shed EDR hooks, anti-VM checks against VMware, VirtualBox, Hyper-V, QEMU, Xen and Parallels, and in-memory hosting of the .NET runtime.
That loader unpacks monitor.raw, a custom encrypted archive with 1,128 index entries covering 315 folders and 806 files. Inside sits a task script in the malware's own scripting language that re-creates the HKCU Run key every 150 seconds and the scheduled task every 875 seconds, both named "Canon Configuration Reader". Cleanup order matters: kill the process first, then remove both persistence entries, or they return within minutes. The archive also carries the final payload, 1.58 MB of RAT shellcode.
The RAT's roughly 1,500 decrypted strings describe remote desktop sessions and screen broadcasts, camera, microphone and system audio capture, a file manager that searches file contents across the host, support for 17 browsers, and the ability to drop and run EXE, DLL, MSI and script payloads. It inventories installed antivirus and Defender status through WMI before anything else. Its command-and-control endpoint, which the strings call the "Gate", is resolved over DNS-over-HTTPS through Cloudflare, Google and Quad9, so the lookups never appear in local DNS logs. On the hosts Huntress investigated, the usual next move was dropping a signed GOMCam2024.exe that launched Chrome with a throwaway profile under %TEMP%.
Version two swaps the wrapping, keeps the engine
The replacement GPT delivered the same chain in new clothes. Stardock's signed DeElevate64.exe became the host binary, with Stardock's own DeElevator64.dll patched the same way, and the loader moved out of the WAV into a genuine Microsoft NuGet package called Build.dat, where an implant inside already-random compressed data has no visible seam. Delivery also hardened: the stage-two script is re-obfuscated on every request, so its hash is worthless as an indicator, and the downloader retries three times, spoofs a Chrome user agent, and strips the Mark-of-the-Web from the MSI so SmartScreen never fires. Under all of it, the RAT is byte-for-byte identical to version one, and Huntress found a third installer staged on the same delivery server. Expect more signed-application swaps, which is why detections keyed to Canon or Stardock names age fast.
Detections that survive the next signed-app swap
Huntress leans on process and persistence behavior, since most of this chain lives in memory or inside files that look harmless:
- powershell.exe launching msiexec.exe against a GUID-named MSI in %TEMP%
- COTFileReadApp.exe or DeElevate64.exe running from a fake product folder under %LOCALAPPDATA%\Programs, especially when msiexec starts it
- a Run value and a scheduled task sharing one name, reappearing shortly after deletion
- unsigned DLLs sitting beside a signed vendor binary, or a patched DLL whose header checksum no longer matches its contents
Do not block the signed Canon or Stardock hosts outright; they are legitimate software. Huntress principal analyst Jonathan Semon told Dark Reading that training has to shift from "check where it came from" to "check what it's asking you to do," because every domain in the entry path was trusted. His rule: no website, chatbot, support page or verification tool has a legitimate reason to tell you to paste a command into PowerShell or any terminal.
The entry point is also a shadow AI problem. Employees searching for "chatgpt" on their own and clicking whatever sits at the top of the results page is the same unsanctioned pattern behind the employee-driven AI use we documented on shadow AI. If you alert on PowerShell download cradles such as irm output piped straight into execution, that single rule catches the first hop of this chain, and version two's per-request re-obfuscation does nothing to evade it.
// Drafted with AI assistance from the sources above and published automatically.