2026-10-04NOTABLEHuntress: a ChatGPT Custom GPT lure feeds a ClickFix chain that ends in a signed-host DLL sideload and a RAT
ChatGPT Custom GPT ClickFix RAT campaign
campaign · campaign:chatgpt-custom-gpt-clickfix-rat-2026-09 single-source
September 2026 campaign in which an attacker-built ChatGPT Custom GPT, in some incidents reached through a Google sponsored result, sends visitors to a Google Sites ClickFix page that delivers a signed-host DLL-sideloaded, in-memory remote access trojan; Huntress counts at least 40 incidents from the Google Sites domain, two confirmed through a Custom GPT (Huntress, 2026-09-28).
Aliases: Plus 5.6 Custom GPT campaign
Coverage
1
first 2026-10-04 → last 2026-10-04
Latest activity
2026-10-04
Huntress: a ChatGPT Custom GPT lure feeds a ClickFix chain that ends in a signed-host DLL sideload and a RAT
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
1
1 hosts
Defender insights
What each entry about ChatGPT Custom GPT ClickFix RAT campaign tells a defender to do, newest first.
Triage · detection
Story timeline
ATT&CK techniques (19 across 9 tactics)
19 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentAcquire Infrastructure: Malvertising
- ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · User Execution: Malicious Copy and Paste · Hijack Execution Flow: DLL
- PersistenceScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information · Masquerading: Match Legitimate Resource Name or Location · Indicator Removal: File Deletion · Deobfuscate/Decode Files or Information · System Binary Proxy Execution: Msiexec · Virtualization/Sandbox Evasion · Hijack Execution Flow: DLL · Reflective Code Loading
- Defense ImpairmentSubvert Trust Controls: Mark-of-the-Web Bypass · Disable or Modify Tools
- DiscoveryVirtualization/Sandbox Evasion
- CollectionScreen Capture · Audio Capture · Video Capture
- Command and ControlIngress Tool Transfer
Resource Development TA0042
T1583.008Acquire Infrastructure: Malvertising×1
Adversaries may purchase online advertisements that can be abused to distribute malware to victims. Ads can be purchased to plant as well as favorably position artifacts in specific locations online, such as prominently placed within search engine results. These ads may make it more difficult for users to distinguish between actual search results and advertisements. Purchased ads may also target specific audiences using the advertising network’s capabilities, potentially further taking advantage of the trust inherently given to search engines and popular websites.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1070.004Indicator Removal: File Deletion×1
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1218.007System Binary Proxy Execution: Msiexec×1
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1497Virtualization/Sandbox Evasion×1
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1620Reflective Code Loading×1
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Defense Impairment TA0112
T1553.005Subvert Trust Controls: Mark-of-the-Web Bypass×1
Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named <code>Zone.Identifier</code> with a specific value known as the MOTW. Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in Protected View. Executables tagged with the MOTW will be processed by Windows Defender SmartScreen that compares files with an allowlist of well-known executables. If the file is not known/trusted, SmartScreen will prevent the execution and warn the user not to run it.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Discovery TA0007
T1497Virtualization/Sandbox Evasion×1
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Collection TA0009
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1123Audio Capture×1
An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
T1125Video Capture×1
An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-10-04/chatgpt-custom-gpt-clickfix-sideloaded-in-memory-rat · ATT&CK page ↗
Entries about ChatGPT Custom GPT ClickFix RAT campaign (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- huntress.com1 (100%)