As reported by SecurityAffairs, Huntress researchers have documented a campaign involving at least 40 incidents where attackers weaponized ChatGPT's Custom GPT feature alongside the ClickFix technique to deliver a sophisticated multi-stage remote access trojan. The campaign is notable not for its technical sophistication alone, but for what it reveals about the evolving economics of trust exploitation.

Threat Alert: As reported by SecurityAffairs, Huntress researchers have documented a campaign involving at least 40 incidents where attackers weaponized ChatGPT's Custom GPT feature alongside the ClickFix technique to deliver a sophisticated multi-stage remote access trojan.

The Platform Trust Problem

The most significant development here isn't the malware payload—it's the abuse of chatgpt.com as a delivery surface. For years, defenders have trained users to verify URLs, look for HTTPS, and check domain legitimacy. This campaign exploits the fact that the real ChatGPT domain is the attack surface. A malicious Custom GPT hosted on the legitimate platform inherits every visual and structural trust signal that users have been taught to rely on. No spoofed domain, no lookalike TLS certificate, no hijacked email—just a feature working as designed, weaponized through social engineering.

The attack chain doesn't need to defeat technical controls. It needs to defeat the assumption that being on a legitimate platform means being safe.

This is the same trust-transfer pattern we've seen with cloud storage services, SaaS collaboration platforms, and now AI tooling. The platform's brand becomes the attacker's camouflage.

ClickFix Is Still Working—And That's a Detection Gap

The fact that ClickFix—a technique that asks users to manually copy a PowerShell command into the Run dialog—continues to succeed across dozens of incidents indicates that user education programs are not keeping pace with attacker creativity. Organizations investing heavily in phishing awareness training should be asking why clipboard-to-execution attacks still have viable conversion rates in 2026.

From a defensive standpoint, this is a process execution control problem, not a phishing detection problem. By the time a user pastes a command into cmd.exe or powershell.exe via the Run dialog, most email and web filtering have already been bypassed. The control point that matters is endpoint execution policy—specifically, whether your environment permits arbitrary PowerShell execution from interactive user sessions.

Technical Indicators Worth Flagging

ClickFix Is Still Working—And That's a Detection Gap
Decimal IP encoding in the PowerShell stage—a trivial obfuscation that bypasses some URL filtering and logging pipelines that pattern-match on dotted-quad notation
In-memory script decoding via a 27,000-character obfuscated payload—nothing hits disk in readable form, meaning file-based AV and static scanning are insufficient
DLL sideloading using legitimately signed executables (Canon and Stardock)—the campaign leverages code signing trust, meaning application control solutions that trust signed binaries by default will not catch this
Dual persistence via Run key and scheduled task—redundancy ensures survival even if one mechanism is cleaned
MSI hiding from the installed programs list—defenders running periodic software audits will miss it

The Whack-a-Mole Reality

Huntress reported the first malicious GPT to OpenAI, which removed it on September 25. A replacement appeared within 48 hours. This is the central tension: platform features designed for openness and rapid deployment are inherently difficult to police at scale. Abuse reporting is reactive, and takedowns are always one step behind attacker reconstitution. Organizations cannot rely on platform-level moderation as a meaningful control.

What You Should Do

Endpoint Hardening

  • Restrict PowerShell execution for standard users via AppLocker or Windows Defender Application Control (WDAC). Enforce Constrained Language Mode for interactive sessions.
  • Enable and tune AMSI integration so in-memory script content is scanned by Defender or your EDR rather than just file-based payloads.
  • Block MSI execution from user-writable locations. The payload ISOSimple.msi should not execute from temp or user profile paths—enforce this via application control policy.
  • Detect DLL sideloading: Monitor for signed, legitimate executables loading DLLs from non-standard directories. EDR platforms with behavioral correlation can flag this pattern.

Detection Engineering

  • Build a detection rule for decimal IP format usage in PowerShell command lines—a regex like \b\d{8,}\b in process command-line logs is a high-signal, low-noise indicator.
  • Alert on scheduled task creation paired with Run key modification within a short time window—this dual-persistence pattern is unusual for legitimate software.
  • Monitor for Canon or Stardock signed executables executing from unexpected paths or loading unsigned DLLs.

User-Facing Controls

  • Update phishing training to explicitly cover clipboard-paste social engineering (ClickFix). Users should understand that no legitimate service will ask them to paste a command into Run.
  • Restrict access to Custom GPTs and third-party AI tools via web filtering policy where feasible, or at minimum flag chatgpt.com interactions for awareness training.
  • Consider clipboard monitoring on managed endpoints to detect when PowerShell code is being pasted into the Run dialog from an external source.

Governance

  • Document AI platform usage in your acceptable use policy. Define whether interacting with third-party Custom GPTs is permitted and under what conditions.
  • Include AI-tooling abuse scenarios in your incident response playbook. This campaign will be replicated—the pattern is now public knowledge.

Bottom Line

This campaign illustrates a structural shift: as AI platforms become primary collaboration surfaces, they also become primary attack surfaces. The malware is pedestrian; the delivery mechanism is the innovation. Defenders who focus only on the payload will miss the next wave. Those who understand trust-transfer dynamics and harden the execution layer will catch this and its inevitable successors.