Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT

Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Table of Contents
    Add a header to begin generating the table of contents

    Threat actors are promoting custom variants of OpenAI’s ChatGPT through sponsored Google search results that impersonate legitimate products, then using ClickFix-style social engineering to trick victims into executing PowerShell commands that deploy remote access trojan malware.

    Sponsored Search Ads Impersonate Legitimate ChatGPT Products

    The campaign works by placing paid search advertisements that appear when users search for ChatGPT-related tools, positioning malicious listings alongside or in place of legitimate results. Victims who click through the sponsored ad are directed to a malicious site rather than an official OpenAI resource, exploiting the trust users place in top search results and the ChatGPT brand itself.

    ClickFix Technique Tricks Victims Into Running PowerShell Commands

    Once on the malicious site, the campaign uses ClickFix-style social engineering, a technique that presents victims with instructions framed as a fix for a technical problem, such as a supposed verification or error-resolution step, that actually directs them to copy and execute a PowerShell command. Victims who follow the on-screen instructions and run the command trigger the deployment of remote access trojan malware onto their machine, giving the attacker remote control over the infected system.

    The technique’s effectiveness rests on convincing a victim to perform the technically risky step themselves, copying and pasting a command into their own operating system, rather than requiring the attacker to deliver and execute a malicious file directly. Because the victim initiates the action, many endpoint protections that watch for suspicious file downloads or attachment behavior do not intervene at the point where the actual compromise occurs.

    Distribution Method Differs From Earlier September ClickFix Campaign

    This campaign’s reliance on paid search advertising to reach users actively searching for AI tools is a distinct distribution method from a separate blockchain-command-and-control ClickFix campaign reported earlier in September, which used a different infrastructure approach. The two campaigns share the underlying ClickFix social-engineering technique but represent separate operations with different delivery mechanisms and, based on current reporting, different infrastructure.

    The recurrence of the ClickFix technique across separate, differently infrastructured campaigns within the same month indicates the method has been adopted independently by more than one group of operators, rather than spreading through a single shared toolkit or affiliate network. Each campaign built its own distribution channel around the same core social-engineering step of getting a victim to run a copied command.

    Sponsored Ads Reach a Security-Naive Audience Searching for AI Tools

    By buying placement in search results for ChatGPT and related AI-tool queries, the campaign’s operators reach users who are actively looking to install a generative-AI product and may be less likely to scrutinize the source of a top search result, particularly a paid listing that appears alongside genuine ChatGPT-related content. That audience, drawn by interest in AI tools rather than any particular technical sophistication, broadens the pool of potential victims beyond the more targeted phishing campaigns typically associated with RAT delivery.

    Researchers Are Reporting the Malicious Ads for Takedown

    Security researchers are tracking the campaign’s malicious advertisements and reporting them to Google for takedown. Guidance issued alongside the disclosure calls for users to avoid installing AI tools through sponsored search results and to verify official OpenAI and ChatGPT domains directly rather than trusting a search ad’s landing page. Organizations have also been advised to block execution of unsolicited PowerShell commands triggered by browser prompts, a control that would interrupt the ClickFix chain at the point where victims are asked to run the malicious command.

    The campaign’s reliance on paid advertising rather than compromised legitimate infrastructure means takedown of individual ads does not necessarily stop the operators from purchasing new placements under different account details, a persistent challenge for ad-platform enforcement against this style of malvertising. The RAT payload’s specific family and capabilities have not been detailed in current reporting on the campaign, leaving the post-infection impact on victim machines less defined than the delivery mechanism itself.

    Related Posts