Full Report
Huntress researchers reveal how attackers are exploiting ChatGPT Custom GPTs to spread ClickFix lures and DLL-sideloaded malware. See the full breakdown.
Analysis Summary
# Tool/Technique: ChatGPT Custom GPT Phishing & ClickFix Lure
## Overview
This attack involves the abuse of legitimate AI infrastructure—specifically **ChatGPT Custom GPTs**—to establish trust with victims. Attackers create custom AI personas that impersonate legitimate software or support services. When a user interacts with the GPT, it provides a link to a malicious "backup" site (often hosted on Google Sites). This site employs the **ClickFix** technique, tricking users into copying and pasting a malicious PowerShell command into their terminal, ultimately leading to the installation of a Remote Access Trojan (RAT).
## Technical Details
- **Type:** Technique (Social Engineering / Living-off-the-Land) and Malware (RAT)
- **Platform:** Windows (Target), Web-based (Delivery)
- **Capabilities:** Credential theft, remote access, DLL sideloading, evasion of EDR/AV via signed binaries, and multi-stage persistence.
- **First Seen:** September 2026 (Reported by Huntress)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.003 - Phishing: Spearphishing Service (Abuse of Custom GPTs)
- **TA0002 - Execution**
- T1059.001 - Command and Scripting Interpreter: PowerShell
- T1204.002 - User Execution: Malicious File
- **TA0005 - Defense Evasion**
- T1574.002 - Hijack Execution Flow: DLL Side-Loading
- T1027 - Obfuscated Files or Information
- **TA0003 - Persistence**
- T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
## Functionality
### Core Capabilities
- **AI-Driven Social Engineering:** Uses the trusted `chatgpt.com` domain to provide instructions, making the lure appear legitimate.
- **ClickFix Lure:** Displays a fake "Update" or "Fix" prompt on a website that instructs the user to press `Win+R`, `Ctrl+V`, and `Enter`. This executes a malicious PowerShell command stored in the user's clipboard.
- **MSI Deployment:** Downloads and installs a malicious MSI package that drops the payload and necessary legitimate binaries for sideloading.
### Advanced Features
- **DLL Sideloading:** Uses a legitimate, signed executable (e.g., `COTFileReadApp.exe` by Canon or a Stardock-signed binary) to load a malicious DLL (`libcef.dll` or similar). This allows the malware to run under the context of a trusted process.
- **Dual Persistence:** Establishes persistence via both the Windows Startup folder and Registry Run keys to ensure the RAT survives reboots.
## Indicators of Compromise
*Note: Specific hashes were not fully detailed in the provided snippet, but patterns are identified below.*
- **File Names:**
- `COTFileReadApp.exe` (Legitimate Canon binary)
- `libcef.dll` (Malicious sideloaded DLL)
- `ActionCenter.exe` (Stardock-signed binary used in later waves)
- **Network Indicators:**
- `chatgpt[.]com/g/g-xxxxxx` (Attacker-controlled Custom GPTs)
- `sites[.]google[.]com/view/[malicious-site]`
- `[C2-IP-or-Domain]` (Defanged C2 infrastructure typically follows MSI execution)
- **Behavioral Indicators:**
- `powershell.exe` execution involving `Get-Clipboard` or `Invoke-Expression` (IEX).
- Unexpected network connections from signed Canon or Stardock utilities.
- Manual creation of LNK files in the `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` directory.
## Associated Threat Actors
- Unknown (Current activity is tracked as a widespread ClickFix campaign variant).
## Detection Methods
- **Signature-based detection:** Monitoring for known malicious MSI hashes and non-standard versions of `libcef.dll`.
- **Behavioral detection:**
- Flagging PowerShell processes that execute commands directly from the clipboard.
- Detecting DLL Sideloading by monitoring signed binaries loading DLLs from unexpected or non-standard paths.
- Monitoring for new, unrecognized Custom GPT URLs in web logs.
## Mitigation Strategies
- **Prevention measures:** Implement "Attack Surface Reduction" (ASR) rules to block process creations from Office or web browsers, and restrict the use of PowerShell for standard users.
- **Hardening recommendations:** Educate users specifically on the "ClickFix" tactic (copy-pasting into Terminal). Use web filtering to block known malicious Google Sites subdomains.
- **AI Policy:** Restrict access to Custom GPTs within the enterprise if they are not required for business functions.
## Related Tools/Techniques
- **ClearFake:** A similar campaign using fake browser update overlays.
- **Lumma Stealer:** Often delivered via similar ClickFix/FakeUpdate mechanisms.
- **DLL Sideloading:** A common technique used by APTs to bypass security software.