
Malicious ChatGPT Custom GPTs Turn ClickFix Into a RAT Lure
Published by AINave Editorial
A malicious custom GPT called “Plus 5.6” turned a familiar ChatGPT interface into the first step of a ClickFix malware campaign. The GPT directed users to a Google Sites page posing as a backup site, where a fake Cloudflare check told them to run a PowerShell command. The command, if run, installed a remote access trojan (RAT), according to Huntress’s investigation as reported by BleepingComputer.
That distinction matters: the interface delivered the lure, but the reported compromise depended on the visitor executing the command. The GPT’s presence on the legitimate ChatGPT domain could make the instructions seem more trustworthy, while the actual installation happened through a user-run command on their computer.
The incident count is not a confirmed infection count
Huntress investigated at least 40 incidents connecting to the Google Sites page, but confirmed that only two involved a custom GPT variant. Those figures describe different things: connections to the destination and confirmed involvement of the GPT. They should not be read as 40 confirmed infections.
The attackers promoted custom ChatGPT variants through sponsored Google results. OpenAI had taken down the first GPT by September 25, but researchers found a second GPT linked to the campaign on September 27; it was still active when they published their report. The campaign uses a hosted AI interface as a credibility layer, rather than relying on the model itself to deliver malware.
A signed application helps load the RAT
After a user runs the PowerShell command, the reported chain installs a malicious MSI. That installer launches a legitimate, signed application alongside a modified DLL that loads the malware. Huntress reported that later attacks switched from a Canon-signed host application to a Stardock-signed one, while the payload remained the same.
The RAT could provide remote desktop access, capture audio and camera input, search files, gather information about the host, and run additional payloads. For persistence, the malware created a Windows Registry Run key and a scheduled task, both named “Canon Configuration Reader.” That name is a reported indicator, not a guarantee that every version uses the same host application or naming.
Huntress also described a custom encrypted file system used to conceal the persistence script and RAT. It held an index of 1,128 file or folder entries, each recording details such as its parent, size, and a per-file key. Much of the chain ran in memory or used files that appeared benign, so focusing only on obvious malicious files could miss important activity.
Process behavior offers practical detection clues
Huntress highlighted PowerShell activity that launches msiexec.exe to silently install an MSI from the temporary folder. Other clues include a signed application starting from an unusual location under %LOCALAPPDATA%\Programs\ and the matching Run key and scheduled task returning after deletion.
These are reported detection opportunities, not a complete rule for every variant. The useful signal is the sequence: a user is prompted to run a command, PowerShell starts an installer, and a signed program loads a modified DLL. In this campaign, the trusted-looking GPT and signed host software sit at opposite ends of the same deception chain.
FAQs
msiexec.exe to silently run an MSI from the temporary folder. Other reported clues included a signed application launched from an unusual %LOCALAPPDATA%\Programs\ location and matching Registry Run-key and scheduled-task persistence.


















