Full Report
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
Analysis Summary
# Tool/Technique: ClickFix via Custom GPTs
## Overview
This attack technique leverages custom OpenAI ChatGPT variants (GPTs) promoted through sponsored Google search results to initiate a "ClickFix" social engineering ruse. The goal is to trick users into executing malicious PowerShell commands that deploy a Remote Access Trojan (RAT). By hosting the initial stage on the legitimate `chatgpt.com` domain, the attackers bypass traditional reputation-based web filters and gain user trust.
## Technical Details
- **Type:** Technique (ClickFix / Social Engineering) and Malware Family (Unnamed RAT)
- **Platform:** Windows
- **Capabilities:** Remote desktop access, audio/camera capture, file exfiltration, reconnaissance, and persistence.
- **First Seen:** September 2026 (Reported)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.002 - Phishing: Spearphishing Link (via Sponsored Ads and Custom GPTs)
- **TA0002 - Execution**
- T1059.001 - Command and Scripting Interpreter: PowerShell
- T1204.002 - User Execution: Malicious Link
- **TA0003 - Persistence**
- T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1053.005 - Scheduled Task/Job: Scheduled Task
- **TA0005 - Defense Evasion**
- T1574.002 - Hijack Execution Flow: DLL Side-Loading
- T1027 - Obfuscated Files or Information (Custom Encrypted File System)
- **TA0011 - Command and Control**
- T1219 - Remote Access Software
## Functionality
### Core Capabilities
- **Social Engineering (ClickFix):** Displays a fake "Cloudflare" security check page on Google Sites, instructing users to copy and paste a PowerShell command into their terminal to "fix" a connection issue.
- **DLL Side-Loading:** The infection chain utilizes legitimate, signed binaries (e.g., Canon or Stardock signed apps) to load a modified, malicious DLL, bypassing security software that trusts signed code.
- **In-Memory Execution:** Much of the infection chain resides in memory to evade disk-based signature scanning.
### Advanced Features
- **Custom Encrypted File System:** The attackers utilize a bespoke archive format (a "homemade encrypted zip") containing over 1,000 entries with its own folder tree and per-file encryption keys to hide the RAT and persistence scripts.
- **Persistence Mechanisms:** Creates a redundant persistence structure using both a Windows Registry Run key and a Scheduled Task, both masquerading as "Canon Configuration Reader."
## Indicators of Compromise
- **File Names:**
- `Canon Configuration Reader` (Task/Registry name)
- Various legitimate signed binaries (Canon or Stardock) repurposed for side-loading.
- **Registry Keys:**
- `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Canon Configuration Reader`
- **Network Indicators:**
- `chatgpt[.]com` (Abused legitimate domain)
- `sites[.]google[.]com/view/[redacted]` (Malicious landing pages)
- **Behavioral Indicators:**
- PowerShell launching `msiexec.exe` with silent flags from temporary directories.
- Signed applications executing from non-standard paths within `%LOCALAPPDATA%\Programs\`.
- Recurring scheduled tasks or registry keys that regenerate immediately after deletion.
## Associated Threat Actors
- Unknown (Campaign identified by Huntress; utilizes "ClickFix" tactics common in modern commodity malware delivery).
## Detection Methods
- **Behavioral Detection:** Monitor for instances of PowerShell spawning `msiexec.exe`.
- **Process Monitoring:** Alert on signed binaries (Canon, Stardock, etc.) running from unusual user-profile subdirectories rather than `C:\Program Files\`.
- **Integrity Monitoring:** Track the creation of scheduled tasks and registry run keys with the string "Configuration Reader."
## Mitigation Strategies
- **User Education:** Train users to never copy/paste commands from a website into a terminal (PowerShell/CMD).
- **Ad-Blocking:** Implement enterprise-grade ad-blockers to prevent users from clicking sponsored search results.
- **Execution Prevention:** Use AppLocker or Windows Defender Application Control (WDAC) to restrict the execution of PowerShell and MSI installers from temp directories.
- **Environment Hardening:** Disable or restrict PowerShell for non-administrative users where possible.
## Related Tools/Techniques
- **ClickFix:** A broader class of social engineering where users are told their browser is broken and provided a "fix" command.
- **DLL Side-loading:** A common technique used by APTs and commodity malware to hide behind legitimate processes.
- **ClearFake:** A similar social engineering framework using fake browser update overlays.