SecurityWeek reports that threat actors are weaponizing ChatGPT Custom GPTs — OpenAI's user-built, personalized versions of ChatGPT — as a delivery vehicle for ClickFix-style social engineering. The attackers publish or distribute Custom GPTs that impersonate legitimate software products, IT support assistants, or troubleshooting guides. When a victim interacts with the GPT, it returns what appears to be a benign "fix" for a fabricated problem: instructions to copy and paste a PowerShell command into the Windows Run dialog or a terminal. Executing that command hands the attacker code execution on the victim's machine.
This is a meaningful evolution of the ClickFix technique. ClickFix campaigns traditionally relied on compromised websites, malvertising, and fake CAPTCHA pages to present the malicious "fix." Moving the lure into a Custom GPT gives attackers two advantages: the perceived authority of the OpenAI platform (users inherently trust content generated inside chat.openai.com), and the ability to impersonate a specific product or support persona at scale without hosting any attacker-controlled web infrastructure. The payload delivery happens entirely through copy-paste — the victim does the executing.
No CVE is associated with this activity; this is pure technique abuse of trusted platforms and legitimate Windows tooling. That makes it harder to block with vulnerability management and more dependent on behavioral detection, user hardening, and execution control. If your users have access to generative AI platforms from corporate endpoints, you are in scope.
Technical Analysis
Attack Chain
- Setup: The attacker creates a Custom GPT configured with instructions and branding that mimic a legitimate product — for example, a "troubleshooting assistant" for popular enterprise software, printers, VPN clients, or driver utilities. The GPT is shared via link, promoted through SEO poisoning, malicious ads, or direct phishing.
- Lure: The victim, searching for help with a real or planted error, interacts with the GPT. The GPT responds with convincing step-by-step instructions telling the user to press
Win+R, paste a provided command, and press Enter — the hallmark ClickFix mechanic. - Execution: The pasted command is a PowerShell (or
mshta/cmd) one-liner. It is parented byexplorer.exebecause it was launched from the Run dialog. Typical characteristics:- Download cradles:
iex (iwr ... ),iex (New-Object Net.WebClient).DownloadString(...),curl ... | iex - Obfuscation:
-enc/-EncodedCommandBase64 payloads, string concatenation, reversed strings - Execution policy bypass:
-ep bypass,-ExecutionPolicy Bypass,-w hidden/-WindowStyle Hidden
- Download cradles:
- Payload: The cradle typically pulls a second-stage script that fingerprints the host and delivers infostealers (Lumma, StealC, Vidar-class tooling historically associated with ClickFix) or remote access tooling. Follow-on stages often write to
%TEMP%or%APPDATA%and establish persistence via Run keys or scheduled tasks.
Why This Variant Matters
- No malicious website required. The lure lives on chat.openai.com — a domain that is whitelisted nearly everywhere and increasingly sanctioned for business use. URL filtering and web reputation provide little coverage.
- Trust transfer. Users treat GPT output as authoritative product documentation. The impersonation angle (a GPT branded as a real product's assistant) dramatically increases paste compliance compared to a sketchy webpage.
- User-driven execution defeats exploit-centric controls. There is no exploit to patch. The victim runs the command voluntarily, so EDR telemetry shows a "legitimate" interactive execution — unless you are specifically hunting the parent/child and command-line patterns that distinguish paste-executed commands from normal admin work.
Key Defensive Observable
The single most reliable discriminator in ClickFix telemetry is the process lineage: explorer.exe spawning powershell.exe, pwsh.exe, cmd.exe, mshta.exe, or rundll32.exe with a suspicious command line. The Run dialog and paste-into-terminal workflows both produce this lineage, and legitimate use of Win+R to launch PowerShell with a long encoded or download-cradle command line is exceptionally rare in enterprise environments.
Detection & Response
Sigma Rules
The following rules target the execution behaviors described above. Deploy them against Sysmon or Windows Security 4688 process creation telemetry with command-line logging enabled.
---
title: ClickFix - Script Interpreter Launched From Explorer With Suspicious Command Line
id: 9f2c8a41-6b3d-4e7f-a1c2-5d8e0b4a7f31
status: experimental
description: Detects PowerShell, cmd, or mshta spawned by explorer.exe (consistent with Win+R paste execution in ClickFix campaigns, including Custom GPT lures) carrying encoded commands, download cradles, or execution policy bypasses.
references:
- https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/
- https://attack.mitre.org/techniques/T1059/001/
- https://attack.mitre.org/techniques/T1204/002/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059.001
- attack.t1204.002
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\explorer.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
- '\mshta.exe'
selection_cl:
CommandLine|contains:
- ' -enc'
- ' -ec '
- '-EncodedCommand'
- 'DownloadString'
- 'Invoke-WebRequest'
- 'iwr '
- 'curl '
- '| iex'
- '|iex'
- '-ep bypass'
- '-ExecutionPolicy Bypass'
- 'Set-MpPreference'
condition: selection_parent and selection_child and selection_cl
falsepositives:
- Rare administrative quick-fixes run via the Run dialog; recommend allowlisting by known admin accounts
level: high
---
title: ClickFix - Mshta Executing Remote Or Inline Script Content
id: 2b7e4d90-1a5f-4c8b-9e3d-6f0a2c8b5e47
status: experimental
description: Detects mshta.exe launched from explorer.exe with a URL or inline script argument, a common ClickFix alternative payload path delivered via fake fix instructions including those from malicious Custom GPTs.
references:
- https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/
- https://attack.mitre.org/techniques/T1218/005/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.defense_evasion
- attack.t1218.005
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\explorer.exe'
Image|endswith: '\mshta.exe'
CommandLine|contains:
- 'http://'
- 'https://'
- 'vbscript'
- 'javascript'
condition: selection
falsepositives:
- Legacy line-of-business HTA applications (rarely launched via Run dialog)
level: high
---
title: ClickFix Follow-On - Script Written To User Temp Or AppData And Executed
id: 5c1a9f38-7d2b-4e6a-8f4c-3b9e1d7a6f52
status: experimental
description: Detects PowerShell or cmd executing script files staged in user-writable Temp or AppData locations, consistent with the second-stage execution pattern of ClickFix campaigns.
references:
- https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection_interpreter:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
- '\wscript.exe'
- '\cscript.exe'
selection_path:
CommandLine|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\AppData\Local\'
selection_ext:
CommandLine|contains:
- '.ps1'
- '.bat'
- '.cmd'
- '.vbs'
- '.js'
filter_known:
CommandLine|contains:
- '\AppData\Local\Microsoft\Teams\'
- '\AppData\Local\slack\'
condition: selection_interpreter and selection_path and selection_ext and not filter_known
falsepositives:
- Software updaters and collaboration tool installers staging scripts in AppData; tune the filter list per environment
level: medium
KQL Hunt — Microsoft Sentinel / Defender
This query hunts the core ClickFix lineage across your fleet using Defender for Endpoint process telemetry. Run it over the last 30 days to establish a baseline, then tune the exclusion list for legitimate admin tooling in your environment.
let Lookback = 30d;
let SuspiciousCL = dynamic(["-enc", "-ec ", "EncodedCommand", "DownloadString",
"Invoke-WebRequest", "| iex", "|iex", "iwr ", "curl ",
"-ep bypass", "-ExecutionPolicy Bypass", "FromBase64String"]);
DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe", "pwsh.exe", "cmd.exe", "mshta.exe", "rundll32.exe")
| where ProcessCommandLine has_any (SuspiciousCL)
or (FileName =~ "mshta.exe" and ProcessCommandLine has_any ("http://", "https://"))
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine,
InitiatingProcessFileName, SHA256, ReportId, DeviceId
| order by Timestamp desc
Companion hunt for the network side — PowerShell making outbound connections shortly after an explorer-spawned execution:
let Lookback = 7d;
let PasteExec = DeviceProcessEvents
| where Timestamp > ago(Lookback)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe", "pwsh.exe", "mshta.exe")
| summarize FirstSeen=min(Timestamp) by DeviceId, ProcessId, FileName;
DeviceNetworkEvents
| where Timestamp > ago(Lookback)
| where InitiatingProcessFileName in~ ("powershell.exe", "pwsh.exe", "mshta.exe", "curl.exe")
| join kind=inner PasteExec on DeviceId
| where Timestamp between (FirstSeen .. FirstSeen + 10m)
| where RemoteUrl !endswith ".microsoft.com" and RemoteUrl !endswith ".windows.net"
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine,
RemoteUrl, RemoteIP, RemotePort
| order by Timestamp desc
Velociraptor VQL Hunt
Use this as a fleet-wide hunt artifact to surface live ClickFix-style execution and staged scripts in user-writable directories:
-- ClickFix hunt: explorer-spawned interpreters with suspicious command lines
-- plus staged script artifacts in Temp/AppData
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime,
get_process_info(pid=Ppid).Name AS ParentName
FROM pslist()
WHERE ParentName =~ '(?i)explorer\.exe'
AND Name =~ '(?i)(powershell|pwsh|cmd|mshta|rundll32)\.exe'
AND CommandLine =~ '(?i)(-enc|-ec |EncodedCommand|DownloadString|Invoke-WebRequest|\\| *iex|iwr |curl |ep bypass|FromBase64String|https?://)'
-- ClickFix second stage: recently created scripts in user-writable paths
SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=[
'C:/Users/*/AppData/Local/Temp/**/*.ps1',
'C:/Users/*/AppData/Local/Temp/**/*.bat',
'C:/Users/*/AppData/Local/Temp/**/*.vbs',
'C:/Users/*/AppData/Roaming/**/*.ps1',
'C:/Users/*/AppData/Roaming/**/*.bat'
])
WHERE Mtime > now() - 604800
ORDER BY Mtime DESC
Hardening and Verification Script
This PowerShell script enforces the logging and policy controls that make ClickFix detectable and harder to execute, then verifies the state. Run elevated; test in a pilot OU before broad deployment.
#Requires -RunAsAdministrator
# Security Arsenal - ClickFix / paste-execution hardening & verification
Write-Host "=== ClickFix Hardening & Verification ===" -ForegroundColor Cyan
# 1. Enable PowerShell Script Block Logging and Module Logging (detection foundation)
$sbPath = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'
$modPath = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging'
New-Item -Path $sbPath -Force | Out-Null
Set-ItemProperty -Path $sbPath -Name 'EnableScriptBlockLogging' -Value 1 -Type DWord
New-Item -Path $modPath -Force | Out-Null
Set-ItemProperty -Path $modPath -Name 'EnableModuleLogging' -Value 1 -Type DWord
Write-Host "[+] Script Block and Module Logging enabled" -ForegroundColor Green
# 2. Enable process creation command-line auditing (4688 command line capture)
$auditPath = 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit'
New-Item -Path $auditPath -Force | Out-Null
Set-ItemProperty -Path $auditPath -Name 'ProcessCreationIncludeCmdLine_Enabled' -Value 1 -Type DWord
auditpol /set /subcategory:"Process Creation" /success:enable /failure:enable | Out-Null
Write-Host "[+] Process creation auditing with command line enabled" -ForegroundColor Green
# 3. Enable Microsoft Defender ASR rules that blunt common ClickFix follow-on behavior
# (Audit mode GUIDs below; set to Block (1) after validation)
# d4f940ab-401b-4efc-aadc-ad5f3c50688a = Block all Office applications from creating child processes
# 56a863a9-875e-4185-98a7-b882c64b5ce5 = Block abuse of exploited vulnerable signed drivers
# be9ba2d9-53ea-4cdc-84e5-9b1eeee46550 = Block executable content from email client and webmail
$asrRules = @{
'be9ba2d9-53ea-4cdc-84e5-9b1eeee46550' = 1 # Block executable content from email/webmail
'd4f940ab-401b-4efc-aadc-ad5f3c50688a' = 2 # Office child processes - AUDIT first
}
foreach ($rule in $asrRules.GetEnumerator()) {
Add-MpPreference -AttackSurfaceReductionRules_Ids $rule.Key -AttackSurfaceReductionRules_Actions $rule.Value
Write-Host "[+] ASR rule $($rule.Key) set to action $($rule.Value) (1=Block, 2=Audit)" -ForegroundColor Green
}
# 4. Verification: report current state
Write-Host "`n=== Verification ===" -ForegroundColor Cyan
Write-Host "Script Block Logging: $((Get-ItemProperty $sbPath).EnableScriptBlockLogging)"
Write-Host "4688 CmdLine Auditing: $((Get-ItemProperty $auditPath).ProcessCreationIncludeCmdLine_Enabled)"
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Ids |
ForEach-Object { Write-Host "ASR configured: $_" }
Write-Host "`n[!] Review: consider Constrained Language Mode via WDAC/AppLocker for high-risk user groups." -ForegroundColor Yellow
Write-Host "[!] Review: consider disabling the Run dialog (NoRun=1) for non-admin user populations via GPO." -ForegroundColor Yellow
Remediation and Mitigation
Because there is no patchable vulnerability here, remediation is a combination of platform governance, execution control, and user behavior change:
- Govern generative AI access. Inventory which AI platforms are reachable from corporate endpoints. If your organization sanctions OpenAI, understand that any Custom GPT — including third-party ones impersonating vendors — is reachable through that allowed domain. Route AI usage through managed accounts where feasible, and consider web proxy categorization or DLP inspection for pasted/returned content containing script commands.
- Break the paste-execute mechanic. The Run dialog is the delivery vector. For user populations that do not need it, disable it via Group Policy (
User Configuration > Administrative Templates > Start Menu and Taskbar > Remove Run menu, registryHKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun = 1). - Constrain script execution. Enforce PowerShell Constrained Language Mode via WDAC or AppLocker for standard users, block
mshta.exefor users who do not need HTA applications, and deploy ASR rules per the script above. - Turn on the telemetry. Script Block Logging, Module Logging, and 4688 command-line auditing are prerequisites for every detection in this post. Verify them now — you cannot hunt what you do not log.
- Train users on the specific lure. Update phishing and awareness material to cover ClickFix explicitly: no legitimate support tool, AI assistant, CAPTCHA, or error fix will ever ask you to paste a command into Win+R or a terminal. This one sentence, internalized, neutralizes the entire technique class.
- Report and disrupt. Report impersonating Custom GPTs to OpenAI's abuse channels. If you identify GPT links in phishing or SEO poisoning targeting your brand, pursue takedown and add the GPT share URLs to your threat intelligence feeds and proxy block lists as an additional layer.
- Hunt retroactively. Run the KQL hunt above across the last 30 days. ClickFix executions are loud once you look for the explorer-spawned interpreter lineage — and any hit deserves full triage, including credential exposure assessment for the affected user, since infostealer follow-on is the norm.
Conclusion
ClickFix's migration into ChatGPT Custom GPTs is a reminder that social engineering follows trust. Attackers did not need an exploit — they needed a venue where users lower their guard, and a branded, product-impersonating GPT on a whitelisted domain is exactly that. Defenders cannot patch their way out of this one. The winning play is behavioral: detect the explorer-spawned interpreter lineage, constrain where scripts can run, kill the Run dialog where it is not needed, and make sure every user knows that a "fix" you paste is a payload you execute.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.