Hackers Used Fake Custom ChatGPT Bot and Google Sites to Deliver ClickFix RAT
Hackers used a fake ChatGPT bot and Google Sites to deliver ClickFix attacks that installed a remote access trojan.
The campaign was recently identified by Huntress. According to the report, it was shut down, but a new one appeared within days. The attackers used a ChatGPT feature called Custom GPT, which lets users configure a version of the AI tool with specific instructions, knowledge, files, tools and capabilities, as well as unique names, personalities and conversation starters. Because a Custom GPT is hosted on ChatGPT.com, a link to one can appear trustworthy since its URL begins with “chatgpt.com.”
In this case, the hackers created a Custom GPT named “Plus 5.6.” OpenAI names its models in similar ways, such as “GPT-3.5” and “GPT-5 Pro,” making the name plausible to users who do not closely follow AI industry releases. The Custom GPT was instructed to display a single message regardless of the prompt: “We’re currently experiencing limited availability on the primary domain.” It then told users to navigate to a “backup domain.”
That backup domain was hosted on Google Sites. Google Sites is a legitimate no-code website building service, and the report said it was likely used to make the operation appear legitimate. Visitors to the backup domain were shown a fake troubleshooting prompt in the form of a Cloudflare CAPTCHA check that asked them to copy and paste a piece of code into the Windows Run program. This is the typical ClickFix approach: the victim is shown a fake problem and immediately given a “solution” that executes malicious commands.
The solution downloaded and ran a Remote Access Trojan that Huntress calls “@input.” According to the researchers, the payload gives attackers almost full control of an infected Windows computer. They can view the victim’s screen and operate the device remotely, and they can turn on the webcam, microphone and system audio to watch and listen. They can also search every file on the computer, including document contents, for valuable information. Before doing that, the malware can take stock of the machine by checking what security software is installed, what programs are running and how the device connects to a wider network.
The malware can also download and run additional components and separate strains. In most cases Huntress investigated, it did exactly that without victims noticing, the researchers said. To remain out of sight, @input contacts its operators through encrypted lookouts that blend into ordinary web traffic. Huntress added that the tool appears to be part of a well-maintained, professionally run framework.
Huntress said the campaign affected “dozens” of users, and its SOC responded to “at least 40” incidents stemming from the specific Google Sites domain involved. The researchers reached out to OpenAI, which helped take down the custom GPT on September 25. A new one emerged two days later.