CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

ChatGPT Custom GPT ClickFix RAT campaign

campaign · campaign:chatgpt-custom-gpt-clickfix-rat-2026-09 single-source

September 2026 campaign in which an attacker-built ChatGPT Custom GPT, in some incidents reached through a Google sponsored result, sends visitors to a Google Sites ClickFix page that delivers a signed-host DLL-sideloaded, in-memory remote access trojan; Huntress counts at least 40 incidents from the Google Sites domain, two confirmed through a Custom GPT (Huntress, 2026-09-28).

Aliases: Plus 5.6 Custom GPT campaign

Coverage
1
first 2026-10-04 → last 2026-10-04
Latest activity
2026-10-04
Huntress: a ChatGPT Custom GPT lure feeds a ClickFix chain that ends in a signed-host DLL sideload and a RAT
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
1
1 hosts

Defender insights

What each entry about ChatGPT Custom GPT ClickFix RAT campaign tells a defender to do, newest first.

2026-10-04NOTABLEHuntress: a ChatGPT Custom GPT lure feeds a ClickFix chain that ends in a signed-host DLL sideload and a RAT

Triage · detection

Story timeline

  1. 2026-10-04A malicious ChatGPT Custom GPT sends users to a Google Sites ClickFix page that installs a sideloaded, in-memory RAT
    active-threatsHuntress: a ChatGPT Custom GPT lure feeds a ClickFix chain that ends in a signed-host DLL sideload and a RAT

Hunting pivots

Affected products
ATT&CK techniques (19 across 9 tactics)

19 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Resource DevelopmentAcquire Infrastructure: Malvertising
  • ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · User Execution: Malicious Copy and Paste · Hijack Execution Flow: DLL
  • PersistenceScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Privilege EscalationScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • StealthObfuscated Files or Information · Masquerading: Match Legitimate Resource Name or Location · Indicator Removal: File Deletion · Deobfuscate/Decode Files or Information · System Binary Proxy Execution: Msiexec · Virtualization/Sandbox Evasion · Hijack Execution Flow: DLL · Reflective Code Loading
  • Defense ImpairmentSubvert Trust Controls: Mark-of-the-Web Bypass · Disable or Modify Tools
  • DiscoveryVirtualization/Sandbox Evasion
  • CollectionScreen Capture · Audio Capture · Video Capture
  • Command and ControlIngress Tool Transfer

Resource Development TA0042

T1583.008Acquire Infrastructure: Malvertising×1

Adversaries may purchase online advertisements that can be abused to distribute malware to victims. Ads can be purchased to plant as well as favorably position artifacts in specific locations online, such as prominently placed within search engine results. These ads may make it more difficult for users to distinguish between actual search results and advertisements. Purchased ads may also target specific audiences using the advertising network’s capabilities, potentially further taking advantage of the trust inherently given to search engines and popular websites.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1204.004User Execution: Malicious Copy and Paste×1

An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1070.004Indicator Removal: File Deletion×1

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1218.007System Binary Proxy Execution: Msiexec×1

Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1620Reflective Code Loading×1

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Defense Impairment TA0112

T1553.005Subvert Trust Controls: Mark-of-the-Web Bypass×1

Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named <code>Zone.Identifier</code> with a specific value known as the MOTW. Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in Protected View. Executables tagged with the MOTW will be processed by Windows Defender SmartScreen that compares files with an allowlist of well-known executables. If the file is not known/trusted, SmartScreen will prevent the execution and warn the user not to run it.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Discovery TA0007

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Collection TA0009

T1113Screen Capture×1

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1123Audio Capture×1

An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

T1125Video Capture×1

An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗

Entries about ChatGPT Custom GPT ClickFix RAT campaign (1)

2026-10-04 · view entry permalink →

NOTABLENATOB2

A malicious ChatGPT Custom GPT sends users to a Google Sites ClickFix page that installs a sideloaded, in-memory RAT

Huntress reports a campaign from late September 2026 in which, in some incidents, victims who searched Google for "chatgpt" got a sponsored result that opened an attacker-built Custom GPT on the genuine chatgpt.com domain. It answers any input with a fake service-availability notice pointing to a "backup domain" on Google Sites, which shows a CAPTCHA and tells the user to paste a command into a terminal. The command fetches a layered, obfuscated script from a host written as a single decimal number, so "rules and URL filters that look for a dotted IP address never see one"; the script installs a hidden MSI with msiexec and deletes itself (Huntress, 2026-09-28).

The MSI presents itself as a printer-configuration reader, launches a legitimately signed Canon application, which loads a patched Canon logging DLL whose imports pull in unsigned DLLs; one XOR-decodes shellcode hidden in a file posing as audio. The shellcode bypasses AMSI, unhooks ntdll, runs anti-VM checks and hosts the .NET runtime, then opens a custom encrypted archive holding a persistence script and the remote access trojan. The script re-creates an HKCU Run value every 150 seconds and a scheduled task of the same name every 875 seconds if either is removed. The RAT offers remote desktop, camera, microphone and audio capture, file search and follow-on payload execution, and resolves its command server through DNS-over-HTTPS to public resolvers, "so they never appear in local DNS logs" (Huntress, 2026-09-28).

Huntress has responded to at least 40 incidents from the Google Sites domain and confirmed two through a Custom GPT. OpenAI took the first GPT down as of 2026-09-25; on 2026-09-27 Huntress found a replacement that swaps the signed host for a Stardock application, hides the loader in a Microsoft NuGet package, strips Mark-of-the-Web from the MSI and pulls a second script that is freshly obfuscated on every request, while the RAT is byte-identical (Huntress, 2026-09-28).

Exposure: any Windows endpoint whose user pastes the command; the chain uses no vulnerability, and staff who search for AI assistants are in scope.

Triage: the signed Canon and Stardock host binaries are legitimate (Huntress: do not block globally); the discriminator is the same binary launched by msiexec from a fake product folder under the user profile, beside a same-named Run value and scheduled task that return when deleted (Huntress, 2026-09-28).

has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance

Most ClickFix chains we see are two or three hops: paste a command, download something, run it. This one has eight, and each hop exists to hide the next one.

rules and URL filters that look for a dotted IP address never see one

Detections tied to Canon or Stardock names will miss the next swap.

Kill the process first, then remove both.

Huntress 2026-09-28
threat04 Oct 04:39Zsingle-sourceOpen finding →
Sources: Huntress

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • huntress.com1 (100%)