Back to Intelligence

ClickFix Attacks via Fake Custom ChatGPT Sites: Detection and Defense Guide for RAT Delivery

SA
Security Arsenal Team
September 29, 2026
12 min read

Threat actors are weaponizing the popularity of OpenAI's ChatGPT ecosystem at scale. Security researchers have identified custom ChatGPT variants — promoted through sponsored Google search results — that redirect unsuspecting users to malicious sites. Those sites execute ClickFix attacks, a social engineering technique that tricks victims into manually executing malicious commands on their own machines, ultimately delivering remote access trojan (RAT) malware.

This is not a vulnerability you can patch. It is a human-layer attack that bypasses nearly every perimeter control because the victim executes the payload themselves. If your organization has users searching for AI tools — and in 2026, every organization does — this campaign is a live risk to your endpoints right now.

What Happened

The attack chain, as reported, works as follows:

  1. Malvertising entry point: Threat actors purchase sponsored placements in Google search results for queries related to custom ChatGPTs and GPT builders. These ads appear above organic results, lending them implicit credibility.
  2. Malicious redirect: Clicking the ad routes the victim to an attacker-controlled site impersonating a legitimate AI tool or custom GPT portal.
  3. ClickFix lure: The site presents a fake verification prompt — typically styled as a CAPTCHA, "I am human" checkbox, or an error message claiming the browser needs a fix. The page instructs the user to press Win + R, paste a command (pre-loaded into the clipboard via JavaScript), and hit Enter.
  4. Self-executed payload: The pasted command is typically a PowerShell one-liner that downloads and executes a second-stage payload — a RAT giving the attacker full remote control, credential theft, keylogging, and a foothold for follow-on activity including ransomware staging.

The genius — and the danger — of ClickFix is that it inverts the trust model. Email gateways, secure web gateways, and browser exploit defenses are all designed to stop the machine from executing bad content. ClickFix gets the human to do it, using the Windows Run dialog as the execution vehicle. No exploit, no macro, no malicious attachment — just a convincing instruction.

Technical Analysis

Attack Chain Breakdown

From a defender's perspective, the observable chain looks like this:

  • Clipboard poisoning: JavaScript on the malicious page calls navigator.clipboard.writeText() to silently place the malicious command on the victim's clipboard.
  • Execution via Run dialog: The user pastes the command into Win+R. This produces a distinctive telemetry artifact: explorer.exe spawning cmd.exe, powershell.exe, pwsh.exe, or mshta.exe as a child process — a pattern that is rare in legitimate enterprise use.
  • Payload retrieval: The command commonly uses Invoke-WebRequest / iwr, curl.exe, mshta.exe fetching remote scripts, or base64-encoded PowerShell stages pulling the RAT from attacker infrastructure.
  • Persistence: RAT families delivered this way typically establish persistence via Run registry keys (HKCU\Software\Microsoft\Windows\CurrentVersion\Run), scheduled tasks, or startup folder shortcuts, then beacon to C2 infrastructure.

Affected Platforms

  • Primary target: Windows endpoints (Windows 10/11, all versions) — the Win+R Run dialog technique is Windows-specific.
  • User population: Any employee with internet access searching for AI productivity tools. No software vulnerability is required — a fully patched machine is equally susceptible.

Exploitation Status

This campaign is confirmed active in the wild and distributed through paid advertising infrastructure, meaning its reach is deliberately broad. ClickFix as a technique has seen sustained, growing adoption by initial access brokers and commodity malware operators since its emergence, and its pairing with AI-themed lures and malvertising represents its current evolution in 2026. No CVE applies — this is pure social engineering plus LOLBin abuse.

Detection & Response

The highest-fidelity detection opportunity in this attack is the process parent-child anomaly: explorer.exe spawning scripting or command interpreters with suspicious command lines. Legitimate software almost never launches PowerShell from Explorer with remote-download flags. Build your detections there.

Sigma Rules

YAML
---
title: ClickFix Execution - Explorer Spawning Script Interpreter via Run Dialog
id: 3f8c1a92-7b4e-4d21-9c63-2e5f8a1b6d47
status: experimental
description: Detects ClickFix-style attacks where a user pastes a malicious command into the Windows Run dialog, resulting in explorer.exe spawning cmd, powershell, or mshta. This parent-child relationship is a strong indicator of ClickFix social engineering delivering RAT malware.
references:
  - https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/
  - https://attack.mitre.org/techniques/T1204/002/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1204.002
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\explorer.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\mshta.exe'
  selection_flags:
    CommandLine|contains:
      - 'iwr '
      - 'Invoke-WebRequest'
      - 'Invoke-Expression'
      - 'IEX'
      - 'http://'
      - 'https://'
      - '-enc'
      - '-e '
      - 'FromBase64String'
      - 'curl'
      - 'mshta'
      - 'bit.ly'
      - 'tinyurl'
  condition: selection_parent and selection_child and selection_flags
falsepositives:
  - Rare cases of administrators running ad-hoc commands via the Run dialog
level: high
---
title: ClickFix Clipboard-Lured PowerShell Download Cradle
id: 8d2e5b14-3a9f-4c76-b821-6f4d9e2c5a83
status: experimental
description: Detects PowerShell download cradles commonly delivered through ClickFix clipboard-paste attacks, including encoded commands and web request patterns used to stage RAT payloads.
references:
  - https://www.bleepingcomputer.com/news/security/custom-chatgpts-push-clickfix-attacks-to-deploy-rat-malware/
  - https://attack.mitre.org/techniques/T1059/001/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059.001
  - attack.command_and_control
  - attack.t1105
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
  selection_download:
    CommandLine|contains:
      - 'DownloadString'
      - 'DownloadFile'
      - 'Start-BitsTransfer'
      - 'curl.exe'
      - 'Invoke-RestMethod'
  selection_url:
    CommandLine|contains:
      - 'http://'
      - 'https://'
  condition: selection_img and selection_download and selection_url
falsepositives:
  - Legitimate software deployment scripts in managed environments
  - IT automation frameworks downloading approved tooling
level: medium
---
title: RAT Persistence via Run Key Following Suspicious Execution
id: 5b7a3f69-1c8d-4e52-a394-7d2b6f4c8e15
status: experimental
description: Detects registry Run key modifications by script interpreters or unusual binaries, a common persistence mechanism for RAT malware delivered through ClickFix campaigns.
references:
  - https://attack.mitre.org/techniques/T1060/
  - https://attack.mitre.org/techniques/T1547/001/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.persistence
  - attack.t1547.001
logsource:
  category: registry_set
  product: windows
detection:
  selection_key:
    TargetObject|contains:
      - '\CurrentVersion\Run'
      - '\CurrentVersion\RunOnce'
  selection_value:
    Details|contains:
      - 'powershell'
      - 'mshta'
      - 'cmd /c'
      - 'AppData'
      - 'Temp'
      - 'AppData\Local'
  condition: selection_key and selection_value
falsepositives:
  - Legitimate software registering autostart entries during installation
level: high

KQL — Microsoft Sentinel / Defender

This hunt query targets the ClickFix execution pattern in Defender XDR telemetry — Explorer-spawned script interpreters with remote-download command lines — and joins against follow-on network activity to identify potential RAT staging:

KQL — Microsoft Sentinel / Defender
let timeframe = 24h;
let SuspiciousProcesses = DeviceProcessEvents
| where TimeGenerated > ago(timeframe)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe", "pwsh.exe", "cmd.exe", "mshta.exe")
| where ProcessCommandLine has_any ("iwr", "Invoke-WebRequest", "Invoke-Expression", "IEX",
    "FromBase64String", "-enc", "DownloadString", "DownloadFile", "mshta", "curl")
   or (ProcessCommandLine has "http" and ProcessCommandLine has_any ("|", "&&", ";"))
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine,
    ProcessId, InitiatingProcessFileName, SHA256, FolderPath;
SuspiciousProcesses
| join kind=leftouter (
    DeviceNetworkEvents
    | where TimeGenerated > ago(timeframe)
    | where InitiatingProcessFileName in~ ("powershell.exe", "pwsh.exe", "cmd.exe", "mshta.exe", "rundll32.exe")
    | where RemoteUrl !has_any ("microsoft.com", "windows.com", "live.com", "office.com", "openai.com")
    | project NetworkTime = TimeGenerated, DeviceName, InitiatingProcessFileName,
        RemoteUrl, RemoteIP, RemotePort
) on DeviceName
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine,
    SHA256, FolderPath, RemoteUrl, RemoteIP, RemotePort
| order by TimeGenerated desc

For environments ingesting Sysmon/SecurityEvent via the agent, an equivalent hunt against 4688 process creation events filtered on CreatorProcessName LIKE '%explorer.exe' with the same command-line indicators is a viable fallback.

Velociraptor VQL

Use this artifact to sweep your fleet for the two most telling forensic artifacts of a ClickFix compromise: (1) live suspicious processes matching the download-cradle pattern, and (2) persistence entries in Run keys pointing to script interpreters or user-writable directories:

VQL — Velociraptor
-- Hunt for ClickFix-style execution and RAT persistence artifacts
SELECT * FROM foreach(row={
  SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
  FROM pslist()
  WHERE (CommandLine =~ '(?i)iwr |invoke-webrequest|frombase64string|downloadstring|mshta http'
     AND Name =~ '(?i)powershell|pwsh|cmd|mshta')
}, query={
  SELECT Pid, Name, CommandLine, Username, CreateTime,
         'SuspiciousProcess' AS ArtifactType
  FROM scope()
})
UNION ALL
SELECT * FROM foreach(row={
  SELECT Name AS RegValueName, Data.value AS RegValueData, FullPath
  FROM glob(glob='HKEY_USERS/*/Software/Microsoft/Windows/CurrentVersion/Run/*',
            accessor='registry')
  WHERE Data.value =~ '(?i)powershell|mshta|cmd /c|appdata|\\temp\\'
}, query={
  SELECT FullPath AS CommandLine, RegValueName AS Name,
         RegValueData AS Exe, '' AS Username, '' AS CreateTime,
         'RunKeyPersistence' AS ArtifactType
  FROM scope()
})

Remediation and Hardening Script

This PowerShell script audits endpoints for indicators of a ClickFix compromise — RunMRU evidence of pasted commands, suspicious Run key persistence, and recently spawned explorer-child script processes — and optionally applies a hardening control (disabling mshta, a frequent ClickFix LOLBin):

PowerShell
# ClickFix Compromise Assessment and Hardening Script
# Run elevated. Review findings before taking remediation action.

$report = @()

# 1. Audit RunMRU history for pasted malicious commands (the Win+R artifact)
Write-Host "[*] Auditing RunMRU (Run dialog history) for all user hives..." -ForegroundColor Cyan
Get-ChildItem Registry::HKEY_USERS -ErrorAction SilentlyContinue | Where-Object {
    $_.PSChildName -match '^S-1-5-21'
} | ForEach-Object {
    $sid = $_.PSChildName
    $runMruPath = "Registry::HKEY_USERS\$sid\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU"
    if (Test-Path $runMruPath) {
        $props = Get-ItemProperty -Path $runMruPath -ErrorAction SilentlyContinue
        $props.PSObject.Properties | Where-Object { $_.Name -match '^[a-z]$' } | ForEach-Object {
            $cmd = $_.Value
            if ($cmd -match 'powershell|mshta|iwr|invoke|curl|http|base64|certutil|bitsadmin') {
                $report += [PSCustomObject]@{
                    Finding = 'Suspicious RunMRU entry'
                    User    = $sid
                    Detail  = $cmd
                }
            }
        }
    }
}

# 2. Audit Run/RunOnce persistence keys for LOLBin or user-writable path references
Write-Host "[*] Auditing Run key persistence entries..." -ForegroundColor Cyan
$persistPaths = @(
    'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run',
    'HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce',
    'HKCU:\Software\Microsoft\Windows\CurrentVersion\Run',
    'HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce'
)
foreach ($path in $persistPaths) {
    if (Test-Path $path) {
        Get-ItemProperty -Path $path | ForEach-Object {
            $_.PSObject.Properties | Where-Object { $_.Name -notmatch '^PS' } | ForEach-Object {
                if ($_.Value -match 'powershell|mshta|cmd /c|AppData|\\Temp\\|rundll32.*http') {
                    $report += [PSCustomObject]@{
                        Finding = 'Suspicious persistence entry'
                        User    = $path
                        Detail  = "$($_.Name) = $($_.Value)"
                    }
                }
            }
        }
    }
}

# 3. Check for currently running explorer-spawned script interpreters
Write-Host "[*] Checking live process tree for ClickFix execution pattern..." -ForegroundColor Cyan
$explorerPids = (Get-CimInstance Win32_Process -Filter "Name='explorer.exe'").ProcessId
Get-CimInstance Win32_Process | Where-Object {
    $explorerPids -contains $_.ParentProcessId -and
    $_.Name -match 'powershell|pwsh|cmd|mshta'
} | ForEach-Object {
    $report += [PSCustomObject]@{
        Finding = 'Active suspicious process'
        User    = $_.GetOwner().User
        Detail  = "$($_.Name) [$($_.ProcessId)]: $($_.CommandLine)"
    }
}

# 4. Output findings
if ($report.Count -gt 0) {
    Write-Host "[!] $($report.Count) suspicious finding(s) detected:" -ForegroundColor Red
    $report | Format-Table -AutoSize | Out-String | Write-Host
    $report | Export-Csv -Path "$env:TEMP\ClickFix_Assessment_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv" -NoTypeInformation
} else {
    Write-Host "[+] No ClickFix indicators found." -ForegroundColor Green
}

# 5. Optional hardening: block mshta.exe via Windows Defender Attack Surface Reduction-style rule
# Uncomment to apply after validating no business dependency on mshta:
# New-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Explorer' `
#   -Name 'DisallowRun' -PropertyType DWORD -Value 1 -Force | Out-Null
# New-Item -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Explorer\DisallowRun' -Force | Out-Null
# New-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Explorer\DisallowRun' `
#   -Name '1' -PropertyType String -Value 'mshta.exe' -Force | Out-Null
# Write-Host "[+] mshta.exe blocked via DisallowRun policy." -ForegroundColor Green

# 6. Recommended: enable PowerShell Script Block Logging if not already configured
$sbLogPath = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'
if (-not (Test-Path $sbLogPath)) {
    New-Item -Path $sbLogPath -Force | Out-Null
    New-ItemProperty -Path $sbLogPath -Name 'EnableScriptBlockLogging' -PropertyType DWORD -Value 1 -Force | Out-Null
    Write-Host "[+] PowerShell Script Block Logging enabled." -ForegroundColor Green
} else {
    Write-Host "[+] PowerShell Script Block Logging already configured." -ForegroundColor Green
}

Remediation and Prevention

Because there is no patchable vulnerability here, defense is a layered combination of policy, technical control, and user behavior:

  1. User awareness — the primary control. Train users on one non-negotiable rule: no legitimate website will ever ask you to press Win+R and paste a command. CAPTCHAs and verification widgets never require keyboard shortcuts or command execution. Include ClickFix-specific examples in your next phishing simulation cycle.

  2. Constrain the execution vehicle. Disable or restrict the Run dialog for standard users via Group Policy (User Configuration > Administrative Templates > Start Menu and Taskbar > Remove Run menu from Start Menu). This does not eliminate risk — attackers also lure users into pasting into PowerShell or Terminal windows directly — but it removes the most common ClickFix path.

  3. Block or restrict mshta.exe using Windows Defender Application Control (WDAC), AppLocker, or ASR rules. mshta is a staple of ClickFix download cradles and has virtually no legitimate business use in most environments.

  4. Enforce PowerShell hardening. Enable Script Block Logging, Module Logging, and consider Constrained Language Mode for standard users via WDAC. Deploy the Defender ASR rule "Block execution of potentially obfuscated scripts."

  5. DNS and web filtering. Block newly registered domains and uncategorized sites at the DNS layer (this is where fake GPT portals live). If your secure web gateway supports it, flag clipboard-write JavaScript behavior or inject warnings on pages calling the Clipboard API.

  6. Search hygiene guidance. Publish internal guidance directing users to bookmark official AI tool URLs (chat.openai.com / chatgpt.com) rather than relying on search results — and specifically to distrust sponsored results for software and AI tool queries. Consider pushing these bookmarks via browser policy.

  7. EDR coverage validation. Confirm your EDR is capturing process creation events with full command lines and parent process data. The Sigma rules above are useless without that telemetry. Test them against a simulated ClickFix command in a lab before trusting them in production.

  8. Incident response readiness. If the assessment script flags findings on an endpoint: isolate the host, capture memory, pull RunMRU and prefetch artifacts, and hunt laterally — RAT access is frequently sold or handed off, and the initial infection is often just the beginning of the intrusion timeline.

The Bottom Line

ClickFix succeeds because it exploits the one attack surface no patch can fix: user trust in familiar workflows. The pairing with malvertising for AI tools is calculated — searching for ChatGPT tools is a mainstream, daily activity in every enterprise. Your detection stack needs to treat explorer.exe → script interpreter as a high-fidelity signal, your policy needs to kill the Run-dialog path, and your users need to know that a website asking them to paste a command is always, without exception, an attack.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.