Custom ChatGPT Variants Used in ClickFix Campaign Deploy Remote‑Access Trojan (RAT)
What Happened – Researchers at Huntress observed malicious “custom GPT” models published on OpenAI’s platform that, when invoked, redirected users to a spoofed Google Sites page. The page delivered a PowerShell command which installed a malicious MSI, creating a signed‑application wrapper and a modified DLL that dropped a remote‑access trojan. Dozens of users were exposed; two confirmed incidents involved the custom GPT variant.
Why It Matters for Trust & Control Assurance
- Demonstrates how a legitimate third‑party AI service can be weaponized, highlighting the need for continuous oversight of vendor‑provided AI models.
- The attack bypasses traditional URL‑based filtering because the malicious instructions originate from the trusted
chat.openai.comdomain, stressing the importance of evidence‑driven vendor risk monitoring. - Persistence mechanisms (Run key, scheduled task) and encrypted payload archives illustrate why organizations must maintain auditable logs of execution and configuration changes.
Who Is Affected – SaaS providers, enterprises that embed AI assistants into workflows, and any organization that allows employees to interact with publicly shared custom GPTs (technology, professional services, finance, etc.).
Recommended Actions
- Inventory all external AI services and custom GPTs used within your environment; map them to a vendor‑risk register.
- Enforce strict execution policies for PowerShell and MSI installers originating from unverified sources; log and alert on such activity.
- Implement continuous monitoring of third‑party AI model usage and retain evidence of model provenance for audit readiness.
Technical Notes – The campaign leverages a ClickFix social‑engineering vector (phishing‑style deceptive instructions) to deliver a PowerShell‑based loader that installs a malicious MSI. The RAT gains persistence via a Registry Run key and a scheduled task, and encrypts its payload in a custom archive to evade static analysis. Source: BleepingComputer