Custom ChatGPTs Used in ClickFix Campaign to Deploy Remote Access Malware

Security researchers analyzing AI-assisted vulnerability discovery and exploit trends

Threat researchers at Huntress have documented a campaign that abused custom ChatGPT configurations and sponsored search results to steer users toward ClickFix pages. The pages presented a fake verification step and instructed visitors to run PowerShell commands that installed remote access malware.

Legitimate platforms supplied credibility to the lure

The malicious GPTs were hosted on the legitimate ChatGPT domain and directed users to a backup page on Google Sites. That page imitated a Cloudflare check, then supplied a command that downloaded an MSI package. The installation chain used a signed application and a modified DLL to load the payload.

Huntress said the remote access trojan supported desktop control, audio and camera capture, file searches, host reconnaissance and delivery of additional payloads. Persistence relied on a registry Run key and a scheduled task.

AI-hosted instructions require the same scrutiny as email links

Organizations should block untrusted command execution, monitor suspicious PowerShell and investigate signed binaries loading unexpected DLLs. Search advertisements and AI-hosted guidance should not be treated as trusted software support. Administrators should also review published custom assistants and remove unapproved models from enterprise workflows. SectechMedia follows related risks in its cybersecurity coverage.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *