As reported by Dark Reading, threat actors have evolved the ClickFix attack pattern to weaponize OpenAI's custom GPT ecosystem, using legitimate platform infrastructure as a lure for RAT delivery. This development warrants serious attention from defenders who may still treat AI platform domains as inherently safe.

Threat Alert: As reported by Dark Reading, threat actors have evolved the ClickFix attack pattern to weaponize OpenAI's custom GPT ecosystem, using legitimate platform infrastructure as a lure for RAT delivery.

Why This Campaign Breaks Traditional Assumptions

The core problem here is not a vulnerability in ChatGPT or Google's infrastructure — it is a trust exploitation problem. Security teams have spent years training users to verify URLs, look for HTTPS, and trust recognizable brands. ClickFix attacks invert that training by serving malicious payloads from domains users have been explicitly told are safe.

When a user interacts with a custom GPT hosted on chatgpt.com or sees a prompt instructing them to run a command that references Google-owned infrastructure, their mental threat model often short-circuits. The domain is legitimate. The platform is legitimate. The action being requested feels like a normal troubleshooting step. This is social engineering designed specifically to defeat security awareness training.

Who Is Most Exposed

Why This Campaign Breaks Traditional Assumptions
Mid-market organizations with limited EDR coverage and no custom GPT usage policies — users may freely interact with arbitrary GPTs without oversight.
Help desk and IT-adjacent roles where staff routinely execute troubleshooting instructions from technical sources and may encounter fake 'fix' prompts during normal support workflows.
Organizations without outbound DNS filtering — once the user executes the payload, C2 traffic may blend with legitimate cloud service destinations.
Environments where PowerShell/cmd execution is not restricted via Application Control or WDAC policies.

The Custom GPT Trust Gap

Custom GPTs are community-created and minimally curated before publication. A malicious GPT can present professional branding, accurate-sounding documentation, and step-by-step instructions that are indistinguishable from legitimate AI assistance. The platform's own UI provides an implicit endorsement that the interaction is 'within ChatGPT,' even when the GPT is instructing the user to take external actions. This is a governance gap that OpenAI and similar providers must address — but defenders cannot wait for that to happen.

Shield53 Recommendations

Immediate Actions

  • Update web filtering policies to treat custom GPT landing pages and AI-generated instructions with the same scrutiny as any user-generated content platform. Tag chatgpt.com custom GPT URLs as 'conditional access' where possible.
  • Deploy or update detection rules for ClickFix-typical behaviors: PowerShell execution originating from browser process, clipboard injection patterns, and mshta/wscript spawned from browser context.
  • Restrlist/block PowerShell Constrained Language mode or enable WDAC policies to prevent arbitrary script execution by non-admin users regardless of source.
  • Enable EDR behavioral detection for 'process spawned from browser with command-line arguments' patterns, which are characteristic of ClickFix delivery.

Strategic Defenses

  • Revise security awareness training to explicitly cover AI-assisted social engineering. Tell users: 'Legitimate AI tools will never ask you to copy-paste commands into your terminal or run PowerShell.' This is a concrete, memorable rule.
  • Inventory and govern AI tool usage in your organization. If your team uses custom GPTs, maintain an allowlist of approved GPTs and block the rest at the DNS/proxy layer.
  • Implement DNS-based C2 disruption by subscribing to a threat intel feed that flags newly registered and dynamic DNS domains commonly used as ClickFix C2 infrastructure.
  • Hunt for existing infections — if ClickFix has been active in your environment, look for persistence mechanisms (scheduled tasks, registry Run keys) that may indicate prior successful RAT delivery before detection was in place.

The defining feature of this campaign is that the attack surface is cognitive, not technical. Your users' trust in AI platforms is what the threat actors are exploiting — and that trust will only grow as AI tools become more embedded in daily workflows. Defenders must treat AI-mediated instructions as an untrusted input channel.