Breaking
Cyber CrimeDeveloping Story

Fake ChatGPT GPT Spreads RAT Malware

Huntress found attackers using custom GPTs and Google Sites to deliver a ClickFix RAT called @input, impacting dozens of users.

··3 hours ago·4 min read
brown padlock on black computer keyboard
Photo by FlyD on Unsplash

Security researchers at Huntress have uncovered a malware campaign that exploited OpenAI's custom GPT feature and Google Sites to deliver a remote access trojan (RAT) known as @input. The attackers created a fake ChatGPT model named "Plus 5.6" to lend an air of legitimacy, then redirected victims to a Google Sites page hosting a fake Cloudflare CAPTCHA. This ClickFix-style attack tricked users into running malicious code, ultimately giving attackers full control over infected Windows machines. The campaign, which Huntress says impacted "dozens" of users, highlights how trusted AI platforms are increasingly being weaponized for social engineering.

Abusing legitimate services

At the heart of the scam is ChatGPT's "Custom GPT" feature, which allows users to configure a version of the AI for specific purposes. Attackers created a custom GPT named "Plus 5.6"—a name that sounds plausible given OpenAI's naming conventions like GPT-3.5 and GPT-5 Pro. This GPT was programmed to display a single message regardless of the user's input: "We're currently experiencing limited availability on the primary domain," followed by instructions to visit a "backup domain."

That backup domain was hosted on Google Sites, a legitimate website-building service. The use of Google Sites likely added a veneer of trust, though as Huntress noted, a discerning user might question why OpenAI would rely on Google for a backup domain rather than creating its own redirect. The custom GPT itself was hosted on ChatGPT.com, so victims had little reason to be suspicious when clicking a link from an email or instant message.

Fake CAPTCHA triggers ClickFix

Once on the Google Sites page, visitors were shown a fake Cloudflare CAPTCHA check. This is the hallmark of a ClickFix attack: the victim is presented with a fake problem and an immediate solution. In this case, the "solution" instructed them to copy and paste a piece of code into the Windows Run program. Doing so executed a malicious script that downloaded and launched the @input RAT.

ClickFix attacks have become a favored tactic for delivering malware because they rely on user action rather than software vulnerabilities, making them harder to detect by traditional security tools. The fake CAPTCHA creates a sense of urgency and legitimacy, tricking even cautious users into compromising their own systems.

What @input can do

Once installed, @input gives attackers near-total control over the infected Windows computer. According to Huntress, the RAT can:

  • View the victim's screen and operate the device remotely
  • Activate the webcam, microphone, and system audio to watch and listen
  • Search through every file, including document contents, for valuable information
  • Assess the machine's security software, running programs, and network connections
  • Download and execute additional malware components or separate strains

In most cases Huntress investigated, the malware did download and run additional payloads without the victim noticing. To evade detection, @input communicates with its operators through encrypted channels that blend into normal web traffic. The researchers also noted that the tool appears to be part of a well-maintained, professionally run framework.

Scope and takedown

Huntress says the campaign impacted "dozens" of users, with the company's security operations center responding to "at least 40" incidents tied to the specific Google Sites domain used in the attack. The researchers contacted OpenAI, which helped take down the malicious custom GPT on September 25. However, a new one appeared just two days later, indicating the attackers are quick to adapt.

The use of legitimate platforms like ChatGPT and Google Sites makes this campaign particularly challenging to defend against. Users trust these services, and the attackers exploited that trust to bypass suspicion. The fact that a replacement GPT emerged within days suggests the operators are persistent and likely to continue refining their tactics.

Huntress's warning

In their analysis, Huntress researchers emphasized the sophistication of the operation. They described the RAT as part of a "well-maintained, professionally run framework," signaling that the attackers are not amateurs. The firm's blog post detailing the campaign can be found here.

The researchers also pointed out that the @input RAT uses encrypted lookouts to disguise its traffic, making network detection difficult. This level of operational security suggests the attackers have significant resources and expertise.

Protecting against similar attacks

While this specific campaign has been disrupted, the techniques used are likely to reappear. Users should be wary of any unsolicited messages directing them to ChatGPT custom GPTs or other AI tools, especially if they prompt for unusual actions like copying and pasting code. Legitimate services rarely require such steps for troubleshooting.

Organizations should also educate employees about ClickFix-style attacks and enforce policies that prevent running scripts from untrusted sources. Security teams can monitor for unusual network traffic and use endpoint detection tools to catch RATs like @input. For a comprehensive list of security solutions, see our guide to the best antivirus.

Why it matters

The abuse of trusted AI platforms for malware distribution is a growing trend that poses significant risks to both individuals and businesses. As AI tools become more integrated into daily workflows, attackers will continue to exploit that familiarity. This campaign shows that even services with strong security postures can be leveraged as vectors when user trust is manipulated. For readers, it's a reminder to verify the authenticity of any AI-generated or AI-hosted content, especially when it urges immediate action. For the industry, it underscores the need for platform providers to proactively monitor for malicious use of their features and for security teams to adapt detection strategies to these evolving social engineering tactics.

#malware#chatgpt#clickfix#rat#social engineering

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories