Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit ChatGPT with ClickFix to Spread RAT

Hackers Exploit ChatGPT with ClickFix to Spread RAT

Posted on September 30, 2026 By CWS

Threat actors are increasingly leveraging the capabilities of ChatGPT’s Custom GPTs to disguise malicious software as legitimate offerings. According to cybersecurity firm Huntress, these attackers are directing unsuspecting users to harmful sites using ClickFix tactics, ultimately deploying Remote Access Trojans (RATs). This development, observed in late September 2026, highlights the exploitation of trusted AI platforms for malicious ends.

Understanding Custom GPTs and Their Misuse

Custom GPTs allow users to tailor ChatGPT to perform specific tasks by uploading reference files and defining instructions. While designed to enhance user experience, these features are being misused by cybercriminals. Victims engaging with attacker-created Custom GPTs receive messages containing links to Google Sites, which lead to ClickFix-style attacks that initiate malware downloads.

In these incidents, victims are tricked into downloading a malicious MSI installer via a deceptive notification. This installer uses a DLL sideloading chain to load harmful shellcode, launching a persistence script and RAT payload. Over 40 individuals have reportedly been affected by this campaign.

Mechanism of the Attack

The attack begins with sponsored search results for terms like “chatgpt,” leading users to interact with a Custom GPT named “Plus 5.6.” Users are shown a “Service Availability Notice,” urging them to navigate to a backup Google Sites domain due to purported limitations on the primary site. This redirection employs a fake Cloudflare CAPTCHA, prompting users to execute a PowerShell command that installs malware.

The malicious installer abuses a legitimate Canon-signed binary to sideload a corrupted DLL, which extracts a loader hidden in a .WAV file. This loader then unpacks the trojan, bypassing security mechanisms and conducting anti-virtual machine checks. The trojan is capable of various actions, including stealing data, running remote desktop sessions, and deploying additional malware.

Broader Implications and Future Outlook

These findings are part of a broader trend of exploiting trusted platforms for cyberattacks. Similar ClickFix campaigns involve phishing sites that mimic trusted services like OpenAI Codex and Anthropic Claude to distribute malware. These campaigns often use malvertising and phishing emails to lure victims to malicious domains, leveraging sophisticated techniques like EtherHiding to evade detection.

The persistent abuse of AI platforms and other trusted services for cybercrime underscores the need for enhanced security measures. As threat actors continue to evolve their tactics, organizations must remain vigilant and adopt proactive defenses to protect their systems and users from such sophisticated attacks.

Overall, the misuse of Custom GPTs and ClickFix techniques highlights the challenges of securing AI technologies against sophisticated cyber threats. Stakeholders are urged to stay informed and implement robust security protocols to mitigate the risks posed by these emerging threats.

The Hacker News Tags:AI security, ChatGPT, ClickFix, Custom GPT, Cybersecurity, data theft, Google Sites, Huntress, Malvertising, Malware, Phishing, RAT malware, remote access trojan, social engineering

Post navigation

Previous Post: SectopRAT Variant Concealed in Windows Software Unveiled
Next Post: Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics

Related Posts

APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine The Hacker News
Supply Chain Attacks Surge Amid New Malware Techniques Supply Chain Attacks Surge Amid New Malware Techniques The Hacker News
Assessing the Role of AI in Zero Trust Assessing the Role of AI in Zero Trust The Hacker News
Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants The Hacker News
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog The Hacker News
Google Eliminates AI Workflows Over GitHub Security Flaw Google Eliminates AI Workflows Over GitHub Security Flaw The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
  • Hackers Exploit ChatGPT with ClickFix to Spread RAT
  • SectopRAT Variant Concealed in Windows Software Unveiled
  • Critical NetScaler Zero-Day Exploits Impacting Key Sectors
  • Critical Vulnerability in Cisco SD-WAN Manager Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
  • Hackers Exploit ChatGPT with ClickFix to Spread RAT
  • SectopRAT Variant Concealed in Windows Software Unveiled
  • Critical NetScaler Zero-Day Exploits Impacting Key Sectors
  • Critical Vulnerability in Cisco SD-WAN Manager Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark