Protect.Computer
NEWS

Custom ChatGPT Bots Spread ClickFix Attacks and RAT Malware

· 1 min read · Malicious byte Digital scams
Custom ChatGPT Bots Spread ClickFix Attacks and RAT Malware

Attackers have found a new way to weaponize OpenAI’s ChatGPT platform: they built a fake custom GPT model named “Plus 5.6,” bought Google Ads to promote it in search results, and used it to funnel victims toward a site that installs malware. The malicious custom GPT was hosted on the legitimate ChatGPT.com domain — which lends an air of authenticity — and directed users to an attacker-controlled page on Google Sites. That page displays a fake Cloudflare verification prompt and tells the visitor to run a PowerShell command to “verify” they’re human.

If the command is run, it installs a malicious MSI package that loads a modified DLL alongside a legitimate, signed application. The payload is a full-featured remote access trojan (RAT) with capabilities for remote desktop control, audio and camera capture, file browsing, host reconnaissance, and executing additional payloads. For persistence, the malware creates a Windows Registry Run key and a scheduled task — both named “Canon Configuration Reader” — to survive reboots. Security firm Huntress investigated at least 40 incidents connected to this campaign. OpenAI has announced it will retire custom GPTs on December 11, but until then, attackers can continue to create and promote malicious variants. The broader ClickFix technique — social-engineering victims into running PowerShell by pretending it’s a required step — is increasingly common and effective.

How to check if you’re affected

If you recently clicked a ChatGPT-related Google ad and followed instructions to run a command on your Windows PC, check for signs of compromise. Affected products are any Windows version where the attacker’s installer ran. Look for a scheduled task named “Canon Configuration Reader” (Task Scheduler → Task Scheduler Library) or a Registry Run key with the same name (HKCU\Software\Microsoft\Windows\CurrentVersion\Run). Either entry that you did not create yourself indicates the RAT was installed and the system should be treated as compromised.

Sources

Related reading