Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT Vendor News › Huntress

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix

Huntress, Monday, September 28th, 2026

Huntress found attackers using ChatGPT Custom GPTs to impersonate products and push a ClickFix lure that installs a RAT.

Huntress researchers found two Custom GPTs in one campaign that impersonated legitimate products and directed victims to a malicious backup site via the trusted ChatGPT interface.

A ClickFix lure tricks victims into running PowerShell, which downloads a malicious MSI and starts a multi-stage, obfuscated infection chain whose payload uses dual persistence and DLL sideloading through Canon- and Stardock-signed executables.

Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections.

more →  ·  More from Huntress →