Security & AI news

ClickFix social engineering · By FireAI Security & Research Team · Published

Huntress links malicious custom GPTs and fake verification pages to a remote access trojan on Windows

Huntress traced sponsored search results for ChatGPT to a custom GPT and a fake Cloudflare check page that has users paste commands, installing a remote access trojan on Windows.

A chat bubble with a warning sign and the FireAI detective mascot, next to the words “Fake GPT and CAPTCHA push a Windows RAT.”

Huntress researchers have linked a malicious custom GPT and a fake Cloudflare verification page to a campaign that installs a remote access trojan on Windows computers, BleepingComputer reported on 29 September 2026. Help Net Security reported the same findings the same day [2]. The technique is called ClickFix: the page instructs the visitor to paste a command that the visitor then runs personally.

Background

ClickFix pages imitate a routine check, such as a CAPTCHA or a browser fix, and tell the visitor to copy a line and paste it into a system dialog or a command window. Because the person starts the command, some browser and operating-system safeguards do not intervene. FireAI News has described the technique in earlier items.

What the report describes

Huntress found a custom GPT named "Plus 5.6" promoted in sponsored Google results for the search term "chatgpt". Visitors were sent to a fake Cloudflare CAPTCHA page hosted on Google Sites. The page told them to paste a command, which started a PowerShell chain that downloaded a malicious MSI installer [1][2]. OpenAI removed the first malicious custom GPT, according to Help Net Security [2].

The trojan's reported functions are remote desktop access, audio and camera capture, file searches, host reconnaissance and the running of additional payloads. It launched through legitimately signed executables, first ones signed by Canon and later ones signed by Stardock, and kept itself running through a Registry Run key and a scheduled task both named "Canon Configuration Reader" [1].

Huntress counted at least 40 incidents that stemmed from the Google Sites page involved. Only two of them were confirmed to have come through custom GPT variants, so the scale of the custom-GPT route is small compared with the page's total reach [1].

Implications for Mac users

The campaign as reported targets Windows: the instructions refer to PowerShell and the Run dialog, and neither source mentions macOS [1][2]. A Mac user is not exposed to this payload. The method, however, is not tied to a platform, and a lookalike page could direct a Mac user to paste a command into Terminal. The sponsored-result route is also independent of the operating system.

Recommendations

  1. Open AI assistants from the vendor’s own app or a bookmark, not from a sponsored search result.
  2. Never paste into Terminal, PowerShell or the Run dialog a command that a web page tells you to copy.
  3. Treat a verification page that asks for anything beyond a click as a scam.
  4. If a command was run, disconnect the computer, change passwords from another device and contact the organisation’s IT support.

Relevance to FireAI

FireAI does not recognise fake pages, scan installers or remove software from a computer, and it cannot influence what a person pastes. What it offers on a Mac is visibility and control of outbound traffic: a Terminal command that downloads from a host with no rule triggers a prompt in Alert mode, and Investigate shows the company and country behind it. The Windows payload described here does not run on macOS.

Limitations

The two reports draw on Huntress alone. They do not state how many people saw the sponsored results or how many devices were compromised beyond the 40 incidents linked to the page. They do not identify who operates the campaign.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. BleepingComputer, 29 September 2026: Custom ChatGPTs push ClickFix attacks to deploy RAT malware
  2. Help Net Security, 29 September 2026: Malicious Custom GPT on chatgpt.com lures users into installing a RAT