Fake ChatGPT “Plus 5.6” Uses ClickFix to Install RAT Malware


chatgpt rat malware
Image credit: OpenAI

A malicious campaign is using custom ChatGPT variants promoted through sponsored Google results to spread remote access malware. Huntress says the campaign relies on ClickFix tactics and has already affected dozens of users.

Malicious ChatGPT variant leads users to fake Cloudflare page

The malicious custom GPT, called “Plus 5.6,” directs users to a Google Sites page designed to look like a Cloudflare verification screen.

Instead of completing a normal browser check, victims are instructed to run a PowerShell command on their computers. Huntress linked at least 40 incidents to the malicious Google Sites page.

Running the command installs a malicious MSI package that uses a legitimate signed application alongside a modified DLL to load a remote access trojan.

The RAT gives attackers extensive control over infected systems, including remote desktop access, camera and audio capture, file searches, system reconnaissance, and the ability to execute additional payloads.

Malware creates persistent access to infected PCs

The malware creates persistence through a Registry Run key and a scheduled task. Both use the name “Canon Configuration Reader.”

Much of the attack chain runs in memory or relies on files that appear legitimate, making the infection harder to spot through basic file inspection.

Huntress says defenders should watch for PowerShell launching msiexec.exe to silently install an MSI from the temporary folder.

Other warning signs include signed applications launching from unusual %LOCALAPPDATA%\Programs\ locations and persistence entries that return after administrators delete them.

Attackers quickly changed the campaign

OpenAI removed the first malicious GPT by September 25, but Huntress found another linked GPT on September 27 that remained active when the security company’s report was published.

The attackers also modified their techniques. Newer infections moved from a Canon-signed application to a Stardock-signed application and changed how the loader reached victim systems.

However, the campaign continued delivering the same RAT payload.

The campaign shows how attackers can combine malicious custom GPTs, sponsored search results, fake verification pages, and trusted signed applications to make ClickFix attacks appear more legitimate.

In other OpenAI news, OpenAI released GPT-6.1 Sol, launched Dots, an always-on AI agent, and reopened sign-ups for its $200 Pro plan.

Via BleepingComputer

More about the topics: ChatGPT, Cybersecurity, malware

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages