In late September 2026, Huntress published findings on a campaign that should concern every organization whose employees use ChatGPT — which, at this point, is effectively every organization. Threat actors are abusing ChatGPT Custom GPTs to masquerade as legitimate product offerings, then steering users to attacker-controlled sites that deploy ClickFix lures to deliver remote access trojans (RATs).
This is not a vulnerability in OpenAI's code. It's an abuse of trust. Custom GPTs carry the implicit credibility of the ChatGPT brand, and users have been trained to treat links surfaced by AI assistants as vetted recommendations. Attackers are weaponizing exactly that assumption. The end game is classic ClickFix tradecraft: a fake 'verification' or 'fix this error' page instructs the victim to press Win+R, paste a clipboard-injected command, and press Enter — at which point the victim has personally executed the malware loader. No exploit required. The user is the exploit.
If your SOC isn't hunting for the behavioral signature of ClickFix execution — explorer.exe spawning powershell.exe, mshta.exe, or rundll32.exe with network-referencing command lines — you are blind to this entire class of attack.
Technical Analysis
What Is Being Abused
- ChatGPT Custom GPTs: Threat actors create Custom GPTs that present as legitimate products or services. These GPTs direct users to malicious sites under the guise of downloads, documentation, or product access.
- ClickFix social engineering: The destination sites display fake CAPTCHA checks, 'verify you're human' prompts, or fabricated error messages. The page silently copies a malicious command to the victim's clipboard and instructs them to paste it into the Windows Run dialog (Win+R) or a terminal.
- Payload delivery: The pasted command typically invokes a living-off-the-land binary (LOLBins such as
mshta.exe,powershell.exe, orrundll32.exe) to fetch and execute a second-stage payload from a remote URL, culminating in RAT deployment and command-and-control (C2) establishment.
Why This Attack Chain Is Effective
- Trusted origin: The malicious link is surfaced inside a platform the user already trusts, bypassing the skepticism users apply to email links or ads.
- User-initiated execution: Because the victim manually pastes and runs the command, the parent process is
explorer.exe— not a browser, not an email client. This breaks many email- and browser-centric detection stacks and can slip past application control policies keyed on delivery vector. - No CVE required: There is no software vulnerability here. The technique is entirely social engineering plus LOLBin abuse, which means patching cannot save you. Only behavioral detection and hardening can.
- Clipboard injection: The victim never sees the command before pasting it, defeating 'don't click suspicious links' training. They were told to fix a problem, not run code.
Exploitation Status
- Confirmed active exploitation in the wild, observed by Huntress beginning late September 2026.
- No CVE is associated with this campaign — it is feature abuse, not a software flaw.
- This follows a broader 2025–2026 pattern of threat actors weaponizing features of trusted AI platforms (shared conversations, Custom GPTs, and assistant-generated links) as delivery infrastructure.
Attack Chain (Defender's View)
Custom GPT (disguised product offering)
-> User clicks link to attacker site
-> ClickFix page: fake verification/error prompt
-> Malicious command copied to clipboard
-> User: Win+R, paste, Enter
-> explorer.exe spawns powershell.exe / mshta.exe / rundll32.exe
-> Remote script/HTA downloaded and executed in memory
-> RAT installed, persistence established, C2 beaconing begins
Detection & Response
The highest-fidelity detection point is the process ancestry anomaly: explorer.exe spawning script interpreters or LOLBins with command lines containing URLs or encoded content. Legitimate software almost never does this. Users doing it voluntarily is the entire premise of ClickFix.
Sigma Rules
---
title: ClickFix Execution via Run Dialog - LOLBin Spawned by Explorer
description: Detects powershell, mshta, rundll32, or similar LOLBins spawned directly by explorer.exe with command lines referencing URLs or encoded content, consistent with ClickFix paste-into-Run-dialog execution.
references:
- https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html
- https://attack.mitre.org/techniques/T1059/
- https://attack.mitre.org/techniques/T1204/
author: Security Arsenal
date: 2026/09/30
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\explorer.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\curl.exe'
- '\msiexec.exe'
- '\regsvr32.exe'
selection_cli:
CommandLine|contains:
- 'http://'
- 'https://'
- 'iwr '
- 'iex'
- 'Invoke-WebRequest'
- 'DownloadString'
- 'FromBase64String'
- ' -enc'
- ' -e '
- 'Start-BitsTransfer'
condition: all of selection_*
falsepositives:
- Rare; legitimate admin scripts run via Run dialog with URLs
tags:
- attack.execution
- attack.t1059
- attack.t1204
level: high
---
title: Mshta Remote HTA Execution
description: Detects mshta.exe executing remote HTA content, a common ClickFix loader stage.
references:
- https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html
- https://attack.mitre.org/techniques/T1218/005/
author: Security Arsenal
date: 2026/09/30
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\mshta.exe'
CommandLine|contains:
- 'http://'
- 'https://'
condition: selection
falsepositives:
- Legacy enterprise HTA applications hosted on intranet servers (allow-list internal URLs)
tags:
- attack.defense_evasion
- attack.t1218.005
level: high
---
title: PowerShell Download Cradle With Obfuscation Indicators
description: Detects PowerShell one-liner download cradles with encoding or string-obfuscation patterns typical of ClickFix-delivered RAT loaders.
references:
- https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html
- https://attack.mitre.org/techniques/T1059/001/
- https://attack.mitre.org/techniques/T1027/
author: Security Arsenal
date: 2026/09/30
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
selection_dl:
CommandLine|contains:
- 'DownloadString'
- 'DownloadFile'
- 'Invoke-WebRequest'
- 'iwr '
- 'wget '
- 'Start-BitsTransfer'
selection_obf:
CommandLine|contains:
- 'FromBase64String'
- ' -enc'
- ' -e '
- '| iex'
- 'IEX('
- '[char]'
- '-join'
condition: selection_img and selection_dl and selection_obf
falsepositives:
- Automated deployment tooling (allow-list known management servers)
tags:
- attack.execution
- attack.t1059.001
- attack.t1027
level: high
KQL — Microsoft Sentinel / Defender
This hunt looks across the last 14 days for the ClickFix ancestry pattern plus suspicious clipboard-era payloads reaching out to the network. Tune the allow-list to your environment before deploying as an analytic rule.
// ClickFix hunt: explorer.exe spawning LOLBins with URL/encoded command lines
let lookback = 14d;
let lollbins = dynamic(["powershell.exe","pwsh.exe","mshta.exe","rundll32.exe","wscript.exe","cscript.exe","curl.exe","msiexec.exe","regsvr32.exe"]);
let suspiciousCli = dynamic(["http://","https://","iwr ","iex","Invoke-WebRequest","DownloadString","FromBase64String"," -enc","Start-BitsTransfer"]);
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ (lollbins)
| where ProcessCommandLine has_any (suspiciousCli)
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine,
InitiatingProcessFileName, ProcessId, SHA256, FolderPath
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| project DeviceName, InitiatingProcessId, RemoteUrl, RemoteIP, RemotePort, TimeGenerated
) on DeviceName, $left.ProcessId == $right.InitiatingProcessId
| summarize FirstSeen=min(TimeGenerated), Connections=make_set(RemoteUrl),
RemoteIPs=make_set(RemoteIP)
by DeviceName, AccountName, FileName, ProcessCommandLine, SHA256
| order by FirstSeen desc
Correlate any hit against proxy/DNS logs for the full destination domain, and check whether the source user recently browsed to a newly registered or low-reputation domain — the ClickFix landing page will typically appear in web proxy telemetry minutes before process execution.
Velociraptor VQL
Use this hunt artifact for fleet-wide triage when you suspect ClickFix exposure and need to identify affected endpoints quickly.
-- ClickFix triage: find LOLBins with URL/encoded command lines spawned by explorer.exe
LET parents = SELECT Pid, Name AS ParentName FROM pslist()
SELECT p.Pid, p.Ppid, par.ParentName, p.Name, p.Exe, p.CommandLine, p.Username, p.CreateTime
FROM pslist() AS p
JOIN parents AS par ON p.Ppid = par.Pid
WHERE par.ParentName =~ '(?i)explorer\.exe'
AND p.Name =~ '(?i)powershell|pwsh|mshta|rundll32|wscript|cscript|curl|msiexec|regsvr32'
AND p.CommandLine =~ '(?i)https?://|iwr |iex|downloadstring|frombase64string| -enc|start-bitstransfer'
ORDER BY p.CreateTime DESC
Follow up on positives by collecting the user's Run dialog MRU (HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU) and recent clipboard-adjacent artifacts — RunMRU frequently retains the exact pasted command even after the process exits, giving you the staging URL for infrastructure takedown and retro-hunting.
Remediation & Hardening Script
The following PowerShell audits a host for ClickFix indicators (RunMRU entries), then applies hardening appropriate for standard users. Test before broad deployment — disabling the Run dialog and blocking mshta.exe outbound will break some admin workflows and legacy HTA apps.
# ClickFix audit + hardening script (run elevated; test in a pilot OU first)
# 1) Audit RunMRU for suspicious pasted commands
$runMRU = Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -ErrorAction SilentlyContinue
if ($runMRU) {
$runMRU.PSObject.Properties | Where-Object {
$_.Name -match '^[a-z]$' -and $_.Value -match '(?i)powershell|mshta|rundll32|curl|iwr|https?://| -enc'
} | ForEach-Object { Write-Warning ("Suspicious RunMRU entry: {0} = {1}" -f $_.Name, $_.Value) }
}
# 2) Enable PowerShell Script Block Logging (feeds Sigma/KQL detection)
New-Item -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Force | Out-Null
Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name 'EnableScriptBlockLogging' -Value 1 -Type DWord
# 3) Disable the Run dialog for standard users (breaks the Win+R paste step)
New-Item -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Force | Out-Null
Set-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'NoRun' -Value 1 -Type DWord
# 4) Enable ASR rule: Block execution of potentially obfuscated scripts
Add-MpPreference -AttackSurfaceReductionRules_Ids '5BEB7EFE-FD9A-4556-801D-275E5FFC04CC' -AttackSurfaceReductionRules_Actions Enabled
# 5) Block mshta.exe outbound at the firewall (kills remote HTA staging)
New-NetFirewallRule -DisplayName 'Block mshta.exe Outbound (ClickFix)' -Direction Outbound -Action Block `
-Program "$env:SystemRoot\System32\mshta.exe" -Enabled True -ErrorAction SilentlyContinue
New-NetFirewallRule -DisplayName 'Block mshta.exe Outbound x86 (ClickFix)' -Direction Outbound -Action Block `
-Program "$env:SystemRoot\SysWOW64\mshta.exe" -Enabled True -ErrorAction SilentlyContinue
Write-Output 'ClickFix hardening applied. Review RunMRU warnings above and validate app compatibility.'
Remediation
There is no patch for this threat — remediation is architectural and behavioral:
- Break the Win+R paste step for standard users. Deploy the
NoRunpolicy via GPO to non-admin users. ClickFix collapses if the user can't open a Run dialog. Provide admins a separate, monitored path. - Constrain LOLBins. Block
mshta.exeoutbound at the host firewall or proxy; enforce AppLocker/WDAC rules preventingmshta.exe,wscript.exe, andrundll32.exefrom executing content outside trusted paths. Enable the ASR obfuscated-scripts rule shown above. - Enable and centralize PowerShell Script Block Logging and Module Logging across the fleet — these are the telemetry backbone for every detection in this post.
- Govern AI platform usage. Publish an explicit policy that links surfaced by AI assistants (including Custom GPTs) are untrusted third-party links. Consider restricting Custom GPT browsing/creation through enterprise ChatGPT workspace controls, and report abusive GPTs to OpenAI when identified.
- Update user awareness training. The specific lesson: no legitimate site will ever ask you to paste a command into the Run dialog or terminal to 'verify' yourself. That single sentence, internalized, defeats the entire ClickFix technique regardless of lure dressing.
- Retro-hunt now. Run the KQL and VQL above over the last 30 days. Check RunMRU on any endpoint whose user reports interacting with a 'product' GPT that redirected them off-platform. Treat any hit as a full IR event: RATs imply credential theft and persistence, not just a loader.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.