Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Custom ChatGPT Variants Used in ClickFix Campaign Deploy Remote‑Access Trojan

Huntress identified malicious custom ChatGPT models that redirect victims to a spoofed Google Sites page, delivering a PowerShell command that installs a remote‑access trojan. The abuse of a trusted AI platform underscores the need for continuous vendor‑risk monitoring and auditable control evidence.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Custom ChatGPT Variants Used in ClickFix Campaign Deploy Remote‑Access Trojan (RAT)

What Happened – Researchers at Huntress observed malicious “custom GPT” models published on OpenAI’s platform that, when invoked, redirected users to a spoofed Google Sites page. The page delivered a PowerShell command which installed a malicious MSI, creating a signed‑application wrapper and a modified DLL that dropped a remote‑access trojan. Dozens of users were exposed; two confirmed incidents involved the custom GPT variant.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a legitimate third‑party AI service can be weaponized, highlighting the need for continuous oversight of vendor‑provided AI models.
  • The attack bypasses traditional URL‑based filtering because the malicious instructions originate from the trusted chat.openai.com domain, stressing the importance of evidence‑driven vendor risk monitoring.
  • Persistence mechanisms (Run key, scheduled task) and encrypted payload archives illustrate why organizations must maintain auditable logs of execution and configuration changes.

Who Is Affected – SaaS providers, enterprises that embed AI assistants into workflows, and any organization that allows employees to interact with publicly shared custom GPTs (technology, professional services, finance, etc.).

Recommended Actions

  • Inventory all external AI services and custom GPTs used within your environment; map them to a vendor‑risk register.
  • Enforce strict execution policies for PowerShell and MSI installers originating from unverified sources; log and alert on such activity.
  • Implement continuous monitoring of third‑party AI model usage and retain evidence of model provenance for audit readiness.

Technical Notes – The campaign leverages a ClickFix social‑engineering vector (phishing‑style deceptive instructions) to deliver a PowerShell‑based loader that installs a malicious MSI. The RAT gains persistence via a Registry Run key and a scheduled task, and encrypts its payload in a custom archive to evade static analysis. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →