Fake ChatGPT model lures users into installing a RAT

Published

Somebody searching Google for "chatgpt" this month could click a sponsored result, land on the real chatgpt.com, and still end up with a remote access trojan on their PC. Researchers Mark O'Halloran and Jonathan Semon at Huntress have documented a campaign that abuses ChatGPT's Custom GPT feature as the opening move of a ClickFix attack, and the operators are still at it: after OpenAI removed the first malicious GPT on 25 September, Huntress found a replacement linked to the same campaign two days later.

Huntress says its SOC has responded to at least 40 incidents tied to the Google Sites page used in the attack, and confirmed that two of them started with a Custom GPT. Every early step happens on a brand the victim already trusts.

A fake model called "Plus 5.6"

Custom GPTs are tailored versions of ChatGPT that anyone can build and share. They live on chatgpt.com, with the GPT's name at the top and its builder underneath. The attackers named theirs "Plus 5.6" so it would pass for a new OpenAI model; the only tell is a small "community builder" label.

Whatever the visitor types, the GPT answers with the same "Service Availability Notice", claiming limited availability on the primary domain and offering a "backup domain". That link goes to a Google Sites page dressed up as a Cloudflare CAPTCHA check. It is a ClickFix page: it tells the victim to copy and paste a command into their Terminal, which runs PowerShell on their own machine.

Eight hops, each hiding the next

Huntress says most ClickFix chains it sees have two or three stages. This one has eight. The pasted command pulls a script from a server written as a decimal number (1614733393) instead of a dotted IP, which Windows quietly resolves to 96[.]62[.]224[.]81 while filters looking for a normal IP address see nothing.

That script silently installs an MSI called ISOSimple.msi, posing as "Advanced Printer Configuration Reader" and hidden from Programs and Features. It drops a legitimate, Canon-signed program from Canon CaptureOnTouch, COTFileReadApp.exe, next to a patched copy of Canon's logging DLL. Because Windows loads DLLs from a program's own folder first (a technique called DLL sideloading), the trusted Canon binary ends up loading the attackers' code.

From there the loader is carved out of a .wav file whose audio gives way to ciphertext part of the way through, and the final payload comes out of monitor.raw, a custom encrypted archive holding 806 files. Huntress reads that scripting layer as a sign of a maintained framework: operators can change persistence names, timing or payload just by shipping a new archive.

The RAT at the end offers remote desktop sessions, camera, microphone and system audio capture, awareness of 17 browsers, a file manager that searches file contents across the host, and the ability to run follow-on payloads. It finds its command server through DNS-over-HTTPS via Cloudflare, Google and Quad9, so the lookups never show up in local DNS logs.

Kill the process first, then remove persistence

The implant persists through a User Run key and a scheduled task, both named "Canon Configuration Reader". A script inside the archive re-creates the Run key every 150 seconds and the task every 875 seconds, so Huntress stresses the order: terminate COTFileReadApp.exe first, then delete both entries. In one incident Microsoft Defender quarantined ISOSimple.msi as Trojan:Script/Wacatac.H!ml, but only after it had already run, and the persistence kept the chain alive.

Hunt for COTFileReadApp.exe running outside a real Canon install and for GUID-named MSI files in %TEMP%. Huntress's original report walks through every stage.

Indicators

The eight-stage chain is elaborate, but the lure does the real work: borrowed trust stacked three layers deep, from a Google ad to OpenAI's own domain to a Cloudflare look-alike. The same social engineering has already turned up in other ClickFix operations. As AI assistants become where people start their searches, the pages that look like them will keep attracting this kind of abuse, and "it was on chatgpt.com" will not be proof of anything.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions