Fake ChatGPT GPT Spreads RAT Malware
Huntress found attackers using custom GPTs and Google Sites to deliver a ClickFix RAT called @input, impacting dozens of users.
Security researchers at Huntress have uncovered a malware campaign that exploited OpenAI's custom GPT feature and Google Sites to deliver a remote access trojan (RAT) known as @input. The attackers created a fake ChatGPT model named "Plus 5.6" to lend an air of legitimacy, then redirected victims to a Google Sites page hosting a fake Cloudflare CAPTCHA. This ClickFix-style attack tricked users into running malicious code, ultimately giving attackers full control over infected Windows machines. The campaign, which Huntress says impacted "dozens" of users, highlights how trusted AI platforms are increasingly being weaponized for social engineering.
Abusing legitimate services
At the heart of the scam is ChatGPT's "Custom GPT" feature, which allows users to configure a version of the AI for specific purposes. Attackers created a custom GPT named "Plus 5.6"—a name that sounds plausible given OpenAI's naming conventions like GPT-3.5 and GPT-5 Pro. This GPT was programmed to display a single message regardless of the user's input: "We're currently experiencing limited availability on the primary domain," followed by instructions to visit a "backup domain."
That backup domain was hosted on Google Sites, a legitimate website-building service. The use of Google Sites likely added a veneer of trust, though as Huntress noted, a discerning user might question why OpenAI would rely on Google for a backup domain rather than creating its own redirect. The custom GPT itself was hosted on ChatGPT.com, so victims had little reason to be suspicious when clicking a link from an email or instant message.
Fake CAPTCHA triggers ClickFix
Once on the Google Sites page, visitors were shown a fake Cloudflare CAPTCHA check. This is the hallmark of a ClickFix attack: the victim is presented with a fake problem and an immediate solution. In this case, the "solution" instructed them to copy and paste a piece of code into the Windows Run program. Doing so executed a malicious script that downloaded and launched the @input RAT.
ClickFix attacks have become a favored tactic for delivering malware because they rely on user action rather than software vulnerabilities, making them harder to detect by traditional security tools. The fake CAPTCHA creates a sense of urgency and legitimacy, tricking even cautious users into compromising their own systems.
What @input can do
Once installed, @input gives attackers near-total control over the infected Windows computer. According to Huntress, the RAT can:
- View the victim's screen and operate the device remotely
- Activate the webcam, microphone, and system audio to watch and listen
- Search through every file, including document contents, for valuable information
- Assess the machine's security software, running programs, and network connections
- Download and execute additional malware components or separate strains
In most cases Huntress investigated, the malware did download and run additional payloads without the victim noticing. To evade detection, @input communicates with its operators through encrypted channels that blend into normal web traffic. The researchers also noted that the tool appears to be part of a well-maintained, professionally run framework.
Scope and takedown
Huntress says the campaign impacted "dozens" of users, with the company's security operations center responding to "at least 40" incidents tied to the specific Google Sites domain used in the attack. The researchers contacted OpenAI, which helped take down the malicious custom GPT on September 25. However, a new one appeared just two days later, indicating the attackers are quick to adapt.
The use of legitimate platforms like ChatGPT and Google Sites makes this campaign particularly challenging to defend against. Users trust these services, and the attackers exploited that trust to bypass suspicion. The fact that a replacement GPT emerged within days suggests the operators are persistent and likely to continue refining their tactics.
Huntress's warning
In their analysis, Huntress researchers emphasized the sophistication of the operation. They described the RAT as part of a "well-maintained, professionally run framework," signaling that the attackers are not amateurs. The firm's blog post detailing the campaign can be found here.
The researchers also pointed out that the @input RAT uses encrypted lookouts to disguise its traffic, making network detection difficult. This level of operational security suggests the attackers have significant resources and expertise.
Protecting against similar attacks
While this specific campaign has been disrupted, the techniques used are likely to reappear. Users should be wary of any unsolicited messages directing them to ChatGPT custom GPTs or other AI tools, especially if they prompt for unusual actions like copying and pasting code. Legitimate services rarely require such steps for troubleshooting.
Organizations should also educate employees about ClickFix-style attacks and enforce policies that prevent running scripts from untrusted sources. Security teams can monitor for unusual network traffic and use endpoint detection tools to catch RATs like @input. For a comprehensive list of security solutions, see our guide to the best antivirus.
Why it matters
The abuse of trusted AI platforms for malware distribution is a growing trend that poses significant risks to both individuals and businesses. As AI tools become more integrated into daily workflows, attackers will continue to exploit that familiarity. This campaign shows that even services with strong security postures can be leveraged as vectors when user trust is manipulated. For readers, it's a reminder to verify the authenticity of any AI-generated or AI-hosted content, especially when it urges immediate action. For the industry, it underscores the need for platform providers to proactively monitor for malicious use of their features and for security teams to adapt detection strategies to these evolving social engineering tactics.
Sources
- TechRadar Original source
- Huntress Also reporting
- Read our full guide to the best antivirus Also reporting
Continue Reading
NetScaler Flaw Weaponized for Deep Access
LevelBlue says attackers exploited a critical NetScaler bug to plant web shells, create superuser accounts, and exfiltrate configuration data.
Star Blizzard Refines Phishing Delivery
Microsoft says the Russian state actor's RedFlick chain cuts victim interaction down to a single click while scaling phishing across 100+ targets.
Zimbra Bug Exploited for Mailbox Theft
Microsoft says attackers chained a patched Zimbra command-injection flaw into web shells, credential theft and cloud exfiltration.