A fake chatbot add-on is the newest front door for a ClickFix infection chain. Huntress watched the campaign unfold in late September and counted at least 40 victims.
The trail starts with a paid Google ad for searches such as “chatgpt.” Two Custom GPTs, each labelled “Plus 5.6,” met visitors with a “Service Availability Notice” urging them to use a backup Google Sites domain rather than pay for an upgrade. That page served a bogus Cloudflare CAPTCHA, the ClickFix signature, and coaxed victims into pasting and executing a PowerShell command.
Executing that command fires an MSI installer. It hijacks a Canon-signed binary to sideload a tampered Canon DLL, which in turn extracts a loader buried in a WAV audio file. To stay hidden, the payload disables AMSI, unhooks ntdll.dll to slip past user-mode monitoring, and probes for VMware and other hypervisor artifacts before running.
The resulting trojan reports on antivirus and system state, opens remote desktop sessions, grabs camera, microphone, and system audio, and resolves its command server over DNS-over-HTTPS so lookups never land in local logs.
