Drooid Logo
Back to story perspectives

Full Breakdown

Hackers Weaponize ChatGPT Custom GPTs to Deploy ClickFix Malware

By Drooid · · How we work

How the Attack Operates

In late September 2026, threat actors created a malicious Custom GPT on chatgpt.com called “Plus 5.6.” The site shows a counterfeit Cloudflare CAPTCHA that tells victims to copy a PowerShell command into the Windows Run dialog. The command downloads an MSI installer (“ISOSimple.msi”), which uses a legitimate Canon-signed binary (COTFileReadApp.exe) to sideload a rogue DLL (ceiinfolog.dll). That DLL loads a second unsigned DLL (rdCore.dll), which extracts an encrypted loader hidden inside a WAV file. The loader bypasses AMSI, unhooks ntdll.dll, performs anti-VM checks, and unpacks a Remote Access Trojan (RAT) and a persistence script from an encrypted file system. The RAT contacts its command-and-control server via DNS-over-HTTPS through Cloudflare, Google and Quad9, blending its traffic with ordinary HTTPS requests.

Technical Details of the Payload

  • Infections: Huntress reported at least 40 users infected; its SOC logged “dozens” of incidents linked to the specific Google Sites domain.
  • RAT capabilities: The malware enumerates installed antivirus products, captures screen, webcam, microphone, and system audio; searches file contents across 17 browsers; can launch remote desktop sessions; and drops additional payloads (EXE, DLL, MSI, PowerShell, batch, VBScript, JavaScript).
  • Persistence: A Windows Active Setup registry key maintains the foothold.
  • C2 architecture: The RAT’s strings refer to the command-and-control endpoint as the “Gate,” accessed via DNS-over-HTTPS to avoid local DNS logging.

Official Statements & Responses

OpenAI removed the malicious Custom GPT on September 25 after cooperating with researchers. Within two days a new Custom GPT appeared, showing rapid re-deployment. GuidePoint Security noted that the RAT, originally a general-purpose backdoor, now delivers a real-time banking trojan capable of intercepting login credentials and two-factor codes from major banks and cryptocurrency exchanges as victims type them.

Why It Matters

The abuse shows how adversaries can exploit built-in customization features of trusted AI services to bypass user skepticism. By embedding malicious links in a legitimate-looking AI interface, attackers achieve higher engagement than traditional phishing emails. The combination of AI-driven social engineering with DLL-sideloading and DNS-over-HTTPS C2 raises the detection bar, forcing defenders to monitor interactions with AI platforms in addition to email and web traffic. Harvesting audio, video, and credential data expands the potential impact on both individuals and organizations.

Verbatim Quotes

  • “In the incidents we saw, victims interacted with an attacker-created Custom GPT, which was programmed to respond to their prompts with a message that included a Google Sites link,” — Huntress
  • “Overall, threat actors continue to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT's Custom GPT feature or through Google Sites for hosting a ClickFix attack,” — Huntress