<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt" -->

---
title: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via...
description: Threat actors are abusing ChatGPT&#x27;s Custom GPT feature to lure victims into a ClickFix-style attack that ultimately deploys a full-featured remote access...
canonical: https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix | daily.dev
og:description: Threat actors are abusing ChatGPT&#x27;s Custom GPT feature to lure victims into a ClickFix-style attack that ultimately deploys a full-featured remote access...
og:url: https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt
og:image: https://api.daily.dev/og/posts/7v2bGS9nT.png
og:image:alt: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 22 min read · 0 upvotes · 0 comments

## Summary

Threat actors are abusing ChatGPT's Custom GPT feature to lure victims into a ClickFix-style attack that ultimately deploys a full-featured remote access trojan. Attackers created a fake Custom GPT called "Plus 5.6," promoted via Google Ads, which directs victims to a Google Sites page mimicking a Cloudflare CAPTCHA. Victims are tricked into pasting a PowerShell command that runs an eight-stage infection chain: downloading an obfuscated script, installing a malicious MSI that abuses a legitimate Canon-signed binary (COTFileReadApp.exe) to sideload a patched DLL, hiding a loader inside a .wav file, and unpacking a RAT from a custom encrypted archive (monitor.raw). The RAT supports remote desktop, webcam/mic capture, browser theft, file search, and dropping follow-on payloads, and communicates with its C2 via DNS-over-HTTPS to evade detection. Huntress found and reported the Custom GPT to OpenAI, which took it down, but a new one tied to the same campaign appeared days later. A second version of the campaign swaps the Canon app for a Stardock-signed binary and hides the loader inside a NuGet package instead of a .wav file, but reuses the identical RAT payload. The campaign has affected dozens of victims across at least 40 incidents.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat>

## Questions this post answers

### How are attackers using ChatGPT Custom GPTs to distribute malware?

Attackers create malicious Custom GPTs (such as one titled "Plus 5.6") promoted through Google Ads that, when interacted with, display a fake "Service Availability Notice" directing users to a Google Sites page. That page mimics a Cloudflare CAPTCHA and delivers a ClickFix attack, tricking victims into pasting a PowerShell command that downloads and installs a malicious MSI leading to a remote access trojan.

_Security teams tracking emerging social engineering techniques like this can follow ongoing threat research on daily.dev._

### What is DLL sideloading and how was it used in the Canon app malware chain?

DLL sideloading exploits how Windows loads a DLL by name from a program's own folder before checking elsewhere. Attackers placed a modified, unsigned ceiinfolog.dll (Canon's logging library) next to the legitimate, signed COTFileReadApp.exe, so when the real Canon app loaded its logger, it also pulled in a malicious rdCore.dll listed in the tampered DLL's import table, launching the next stage of the attack.

_Developers investigating DLL sideloading risks in signed applications can dig deeper into similar cases on daily.dev._

### How did attackers hide malware inside a WAV audio file?

A file called Common.Integrator.Preview.wav had a valid RIFF/WAVE header and real audio data for part of its length, but at offset 0x24362 the samples turned into 341,395 bytes of XOR-encrypted ciphertext containing a loader. A rolling single-byte XOR cipher using two stirred counters decoded the bytes into x64 machine code, evading tools that trust file headers rather than inspecting content.

_Malware analysts researching steganography-adjacent payload hiding techniques can track write-ups like this on daily.dev._

## Similar posts on daily.dev

- [ChatGPT share links abused to host fake outage pages to deliver malware](https://daily.dev/posts/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware-h2gq8yzz2) · BleepingComputer · 1 upvotes · 0 comments
- [ClickFix Campaign Generated Via AI Delivers SmartRAT](https://daily.dev/posts/clickfix-campaign-generated-via-ai-delivers-smartrat-r7higkqal) · Security Boulevard · 0 upvotes · 0 comments
- [Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads](https://daily.dev/posts/fake-osint-and-gpt-utility-github-repos-spread-pystorerat-malware-payloads-9jtaz4clq) · The Hacker News · 0 upvotes · 0 comments
- [Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign](https://daily.dev/posts/threat-actors-abuse-claude-ai-shared-chat-for-clickfix-malvertising-campaign-zdoc6dupj) · Trend Micro · 1 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware), [#chatgpt](https://daily.dev/tags/chatgpt)

[View this post on daily.dev](https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix","url":"https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt"},"datePublished":"2026-09-29T07:46:20.166Z","dateModified":"2026-09-30T21:31:26.694Z","description":"Threat actors are abusing ChatGPT's Custom GPT feature to lure victims into a ClickFix-style attack that ultimately deploys a full-featured remote access...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bb214f7ac7bcfb4b039b86b6e107316b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bb214f7ac7bcfb4b039b86b6e107316b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Huntress Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Huntress Blog","logo":"https://media.daily.dev/image/upload/s--kDC1MDsj--/f_auto,q_auto/v1780213277/logos/huntress-blog?_a=BAMAMiWQ0","url":"https://daily.dev/sources/huntress-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware,chatgpt","timeRequired":"PT22M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Huntress Blog","item":"https://daily.dev/sources/huntress-blog"},{"@type":"ListItem","position":3,"name":"Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-7v2bgs9nt#faq","mainEntity":[{"@type":"Question","name":"How are attackers using ChatGPT Custom GPTs to distribute malware?","acceptedAnswer":{"@type":"Answer","text":"Attackers create malicious Custom GPTs (such as one titled \"Plus 5.6\") promoted through Google Ads that, when interacted with, display a fake \"Service Availability Notice\" directing users to a Google Sites page. That page mimics a Cloudflare CAPTCHA and delivers a ClickFix attack, tricking victims into pasting a PowerShell command that downloads and installs a malicious MSI leading to a remote access trojan. Security teams tracking emerging social engineering techniques like this can follow ongoing threat research on daily.dev."}},{"@type":"Question","name":"What is DLL sideloading and how was it used in the Canon app malware chain?","acceptedAnswer":{"@type":"Answer","text":"DLL sideloading exploits how Windows loads a DLL by name from a program's own folder before checking elsewhere. Attackers placed a modified, unsigned ceiinfolog.dll (Canon's logging library) next to the legitimate, signed COTFileReadApp.exe, so when the real Canon app loaded its logger, it also pulled in a malicious rdCore.dll listed in the tampered DLL's import table, launching the next stage of the attack. Developers investigating DLL sideloading risks in signed applications can dig deeper into similar cases on daily.dev."}},{"@type":"Question","name":"How did attackers hide malware inside a WAV audio file?","acceptedAnswer":{"@type":"Answer","text":"A file called Common.Integrator.Preview.wav had a valid RIFF/WAVE header and real audio data for part of its length, but at offset 0x24362 the samples turned into 341,395 bytes of XOR-encrypted ciphertext containing a loader. A rolling single-byte XOR cipher using two stirred counters decoded the bytes into x64 machine code, evading tools that trust file headers rather than inspecting content. Malware analysts researching steganography-adjacent payload hiding techniques can track write-ups like this on daily.dev."}}]}
```

