Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Huntress, Monday, September 28th, 2026
Huntress found attackers using ChatGPT Custom GPTs to impersonate products and push a ClickFix lure that installs a RAT.
Huntress researchers found two Custom GPTs in one campaign that impersonated legitimate products and directed victims to a malicious backup site via the trusted ChatGPT interface.
A ClickFix lure tricks victims into running PowerShell, which downloads a malicious MSI and starts a multi-stage, obfuscated infection chain whose payload uses dual persistence and DLL sideloading through Canon- and Stardock-signed executables.
Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections.