Generative AI chatbots have become everyday work tools. Employees use them to draft emails, summarize documents, brainstorm ideas, and troubleshoot problems. That familiarity is exactly what cybercriminals are now exploiting. Security researchers recently documented a campaign that combines a malicious custom AI assistant, hosted on a legitimate AI platform, with a fake CAPTCHA trick known as “ClickFix” to install a remote access trojan (RAT) on victims’ computers.
At Cytranet, we monitor emerging threats like this one so we can help our customers protect their people, devices, and networks. In this article, we explain how the attack works step by step, why it is so effective, and the practical measures every organization should put in place to defend against it.
First, What Are Custom AI Assistants?
Several leading AI chatbot platforms allow users to build and share customized versions of their assistant. These custom assistants can be given specific instructions, knowledge, and personalities so they perform specialized tasks, such as answering questions about a product, following a business workflow, or helping with a particular type of writing.
Custom assistants are hosted on the AI provider’s own legitimate domain and look nearly identical to the standard chat interface. Used responsibly, they can be genuinely helpful. The problem is that anyone can create one, including attackers. Because the assistant follows whatever instructions its creator provides, a malicious author can program it to deliver fake warnings and recommend dangerous links while appearing to be part of a trusted service.
How the Attack Unfolds, Step by Step
Step 1: A sponsored search result
The attack begins with an ordinary web search. An employee in a hurry searches for the name of a popular AI chatbot and clicks the first result without noticing that it is a sponsored advertisement, a paid placement rather than an organic search result.
Step 2: A convincing look-alike
The ad leads to what appears to be the familiar chatbot interface. In reality, it is a custom assistant created by the attacker, labeled with a name designed to sound like a premium or upgraded version of the real product. Many users would assume it is simply a new release.
Step 3: A fake service notice
When the user types a first question, the assistant does not answer it. Instead, it displays an official-sounding “service availability notice” claiming the main site is experiencing limited availability and recommending a “backup domain.” A link is provided.
Step 4: The fake CAPTCHA
The link opens a page that imitates a well-known website security check. The fake CAPTCHA instructs the visitor to “verify they are human” by copying a command and running it on their computer, for example by pressing a key combination that opens the Run dialog or a terminal and pasting text that the page has silently placed on the clipboard. This is the ClickFix technique.
Step 5: Malware installation
Running the command downloads and installs a remote access trojan. Once active, this type of malware can give attackers extensive control over the infected computer, including:
- Remote desktop control and live screen viewing
- Access to the camera, microphone, and system audio
- Searching and stealing files and stored data
- Running additional malicious scripts and payloads
From there, attackers can harvest credentials, move to other systems on the network, steal sensitive information, or deploy ransomware.
Why This Attack Is So Effective
It exploits trust in familiar tools
Most people would not think twice about opening their favorite AI assistant. Because the malicious assistant runs on the legitimate AI provider’s domain, the address bar looks correct, and traditional advice to “check the URL” does not immediately reveal the problem.
It borrows credibility at every step
The attack chains together trusted elements: a major search engine, a well-known AI platform, and an imitation of a familiar website security check. Each step feels routine, which lowers the victim’s guard.
It turns the user into the installer
ClickFix attacks persuade the victim to run the malicious command themselves. Because the user initiates the action, some security controls that block automatic downloads may never be triggered.
It thrives where AI use is unmanaged
If an organization has no AI usage policy, leadership may not even know which AI tools employees are using. That makes it harder to recognize the source of an infection and slows incident response.
This campaign follows a broader pattern of attackers abusing search engines to reach victims. Our article on SEO poisoning explains how criminals manipulate search results to push malicious sites to the top of the page.
“The most dangerous attacks today do not break through the firewall. They convince a trusted employee to open the door. That is why we always pair technical controls with practical training. A team that knows a real security check will never ask them to paste a command into their computer has already defeated this entire attack.”
Doug Roberts, Chief Technology Officer, Cytranet
How to Protect Your Organization
Defending against this threat comes down to two priorities: awareness and oversight. Employees need to recognize the warning signs, and the organization needs visibility into the tools its people use. Here are the measures we recommend.
1. Teach one simple rule about CAPTCHAs
A legitimate CAPTCHA or website security check will never ask you to copy a command, open the Run dialog, open a terminal, or paste anything into your computer. Real checks ask you to click a box, select images, or solve a simple puzzle. Any “verification” that asks you to run something is an attack. Make this rule part of every security briefing, and encourage employees to contact IT immediately if they encounter one.
2. Bookmark trusted tools and avoid sponsored results
Encourage employees to access AI tools and other business applications through bookmarks or a company portal rather than through search engines. When searching is necessary, teach staff to recognize and skip “Sponsored” results at the top of the page, which attackers can purchase to promote impersonation sites.
3. Understand the difference between a domain and what lives on it
A trusted domain can still host untrusted content. Custom AI assistants, shared documents, forms, and file-sharing links all live on legitimate domains but can be created by anyone. Employees should treat unexpected instructions or links from a custom assistant with the same caution they apply to an unexpected email attachment.
4. Create a clear AI usage policy
An effective AI policy should:
- List approved AI tools and how employees should access them
- Define what information may be entered into AI tools, such as general marketing copy, and what must never be shared, such as customer data, financial records, credentials, or source code
- Specify whether third-party custom assistants may be used
- Explain how to report suspicious AI behavior or security concerns
- Assign responsibility for reviewing and updating the policy
A policy gives you visibility into which tools are in use and makes it far easier to trace the source of an incident.
5. Provide ongoing security awareness training
Annual training is not enough for threats that evolve this quickly. Short, regular sessions and simulated phishing exercises keep employees alert. Include examples of fake CAPTCHAs, impersonated AI tools, malicious search ads, and urgent “service notices.”
6. Restrict who can run scripts and install software
Limit administrative privileges, restrict command-line and scripting tools for users who do not need them, and use application allowlisting where practical. These controls can stop a ClickFix command even if an employee is fooled.
7. Deploy endpoint detection and 24/7 monitoring
Modern endpoint detection and response (EDR) tools can identify suspicious script activity and remote access behavior and isolate infected devices quickly. Pairing EDR with round-the-clock monitoring ensures someone responds even when an infection happens after hours.
8. Use DNS and web filtering
Filtering services can block access to known malicious domains and newly registered sites commonly used in these campaigns, adding a safety net if someone clicks a bad link.
9. Segment your network
Network segmentation limits how far an attacker can move if one computer is compromised. Separating guest Wi-Fi, voice systems, critical servers, and general workstations contains the damage. Cytranet’s managed Wi-Fi and network services can help design segmentation that balances security and usability.
10. Have an incident response plan
Know in advance who employees should call, how infected devices will be isolated, how credentials will be reset, and how backups will be used to restore systems. A rehearsed plan turns a potential crisis into a manageable event. Our guide to cybersecurity and compliance for small businesses offers additional planning guidance.
What to Do If Someone Ran a Suspicious Command
- Disconnect the device from the network immediately, both wired and Wi-Fi.
- Contact your IT team or managed technology partner right away.
- Do not attempt to “clean” the device yourself or continue using it.
- From a different, trusted device, change passwords for email, business applications, and any accounts accessed from the affected computer, and enable multi-factor authentication.
- Let IT review logs and other devices for signs of spread.
Speed matters. The sooner an infected device is isolated, the less opportunity attackers have to steal data or move deeper into the network.
Frequently Asked Questions
Are AI chatbots safe to use at work?
Yes, when used through approved, verified access points and within a clear policy that defines what data may be shared. The risk comes from impersonation and unmanaged use.
How can I tell whether a CAPTCHA is fake?
If it asks you to copy, paste, or run anything on your computer, it is fake. Legitimate checks only ask you to click, select images, or solve a simple puzzle within the web page.
Can antivirus software stop ClickFix attacks?
It may, but because the user runs the command manually, some attacks evade basic protection. Layered defenses, including EDR, privilege restrictions, filtering, and training, are far more effective.
Why are sponsored search results risky?
Ads appear above organic results and can be purchased by anyone who passes the ad platform’s screening. Attackers sometimes slip through and use ads to impersonate popular brands and tools.
Do small businesses really need an AI usage policy?
Yes. Small businesses are frequent targets precisely because they often lack formal policies and dedicated security staff. Even a one-page policy significantly improves visibility and control.
Strengthen Your Defenses With Cytranet
Attackers are turning trusted platforms into weapons, and staying protected requires both informed people and well-managed technology. Cytranet is a Las Vegas-based, licensed telecommunications carrier that helps businesses, nonprofits, and government organizations build secure, resilient networks, with services spanning dedicated fiber and fixed wireless internet, managed Wi-Fi, private data transport, and managed IT and network support. To review your organization’s defenses, call 702-846-5000 or email info@cytranet.com.







