Full Report
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
Analysis Summary
# Tool/Technique: ChatGPT Custom GPT Phishing & ClickFix Delivery
## Overview
This technique involves the weaponization of legitimate AI infrastructure (OpenAI’s Custom GPTs) to host social engineering lures. Threat actors create personalized GPTs that mimic legitimate services to redirect users to "ClickFix" pages. These pages trick users into executing malicious PowerShell commands that deploy a multi-stage Remote Access Trojan (RAT).
## Technical Details
- **Type:** Technique (Social Engineering/Lure) & Malware (Remote Access Trojan)
- **Platform:** Windows (Target), ChatGPT/OpenAI (Delivery)
- **Capabilities:** Persistence, Credential/Data Stealing, AV Evasion, Remote Surveillance, Payload Dropper.
- **First Seen:** September 2026 (Observed by Huntress)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.002 - Phishing: Spearphishing Link (via Custom GPT)
- T1204.002 - User Execution: Malicious File
- **TA0002 - Execution**
- T1059.001 - Command and Scripting Interpreter: PowerShell
- T1204.001 - User Execution: Malicious Link
- **TA0003 - Persistence**
- T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- **TA0005 - Defense Evasion**
- T1574.002 - Hijack Execution Flow: DLL Side-Loading
- T1027.003 - Obfuscation: Steganography (WAV audio files)
- T1562.001 - Impair Defenses: Disable or Modify Tools (AMSI Bypass)
- T1497.001 - Virtualization/Sandbox Evasion: System Checks
- **TA0011 - Command and Control**
- T1071.004 - Application Layer Protocol: DNS (DNS-over-HTTPS)
## Functionality
### Core Capabilities
- **Information Gathering:** Documents system profile, antivirus status, and Microsoft Defender state.
- **Remote Access:** Conducts remote desktop sessions and screen broadcasting.
- **Surveillance:** Captures endpoint camera input, microphone, and system audio.
- **Payload Execution:** Drops and executes secondary `.EXE`, `.DLL`, and `.MSI` files, along with PowerShell, VBScript, and JavaScript.
- **File Management:** Built-in component to search and manage files across the system.
### Advanced Features
- **Multi-Stage Sideloading:** Uses a legitimate Canon-signed binary (`COTFileReadApp.exe`) to load a chain of rogue DLLs.
- **Steganographic Extraction:** Extracts encrypted loaders from `.WAV` audio files (similar to Octowave Loader).
- **Anti-Analysis:** Checks CPU vendor strings against VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels to detect virtual environments.
- **Stealth C2:** Uses DNS-over-HTTPS (DoH) via Cloudflare, Google, and Quad9 to mask command-and-control traffic as legitimate HTTPS requests.
## Indicators of Compromise
- **File Names:**
- `ISOSimple.msi`
- `COTFileReadApp.exe` (Legitimate Canon binary)
- `ceiinfolog.dll` (Altered DLL)
- `rdCore.dll` (Unsigned DLL)
- `Common.Integrator.Preview.wav` (Malicious carrier)
- `monitor.raw` (Encrypted payload)
- **Network Indicators (Defanged):**
- chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6
- chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6
- Google Sites (ClickFix landing pages)
- **Behavioral Indicators:**
- PowerShell execution following a manual copy-paste action from a web browser.
- DNS-over-HTTPS traffic originating from non-browser processes.
## Associated Threat Actors
- **Unknown** (Activity tracked by Huntress; shares TTPs with Octowave Loader campaigns).
## Detection Methods
- **Signature-based:** Detect known rogue DLLs (`ceiinfolog.dll`, `rdCore.dll`) and specific `.WAV` file headers containing encrypted shellcode.
- **Behavioral:** Monitor for `PowerShell.exe` executing base64 commands initiated by browser processes. Alert on DLL side-loading involving `COTFileReadApp.exe`.
- **Network:** Monitor for unusual DNS-over-HTTPS patterns from unsigned binaries or known legitimate apps that do not typically use DoH.
## Mitigation Strategies
- **User Training:** Educate users on "ClickFix" lures—legitimate sites will never ask you to copy/paste PowerShell commands into a terminal.
- **Restricted Execution:** Implement PowerShell Constrained Language Mode and Execution Policies (e.g., `AllSigned`).
- **Application Whitelisting:** Prevent unauthorized MSI installers and unsigned DLLs from running in user-writable directories.
- **AI Governance:** Monitor and restrict organizational access to Custom GPTs if not required for business operations.
## Related Tools/Techniques
- **ClickFix:** A social engineering tactic used to trick users into fixing "browser errors" by running malicious scripts.
- **Octowave Loader:** A loader known for using audio files to hide payloads.
- **Claude Artifacts Abuse:** A similar technique weaponizing Anthropic's AI features.