Hackers Abuse ChatGPT Custom GPTs to Push ClickFix Malware

Kinyua Njeri (Sam Kin)  - Tech Expert
Last updated: October 3, 2026
Human Written
Share
Hackers Abuse ChatGPT Custom GPTs to Push ClickFix Malware
Radar Rundown
  • The Huntress firm discovered that attackers made use of malicious ChatGPT Custom GPTs to lead victims into a ClickFix malware campaign.

  • The chain of infection involved the use of PowerShell, MSI installers, DLL sideloading, persistence strategies plus a remote access trojan.

  • Researchers linked two confirmed infections to malicious Custom GPTs among at least 40 related incidents.

Hackers are utilizing ChatGPT Custom GPTs in a malware operation aimed at persuading individuals into downloading a type of Remote Access Trojan (RAT). Huntress experts discovered the operation after looking into numerous events associated with the same technology.

The attackers used a fake Custom GPT called ‘Plus 5.6’ to make the scheme look legitimate. They then moved victims from the real ChatGPT website to a fake verification page that triggered a ClickFix attack.

Attackers hide behind a trusted ChatGPT interface

Huntress noted that the operation started as the bad actors designed a Custom GPT in the official ChatGPT domain. They called the site ‘Plus 5.6’, which made it appear as a ChatGPT product. Some victims reached the fake GPT while searching for ChatGPT on Google. Paid search results ensured the visibility of the fraudulent website to the victims.

In general, this situation is based on the principles of familiarity. The victims saw the real chatgpt.com and recognized the ChatGPT user interface. This makes the site appear legitimate for anyone who has less knowledge about the operation of Custom GPTs.

Once users had interacted with the malicious chatbot, it showed a fake service message. The notification says that the main ChatGPT page had limited availability. Then it offered a fake backup option, which redirected users to the Google Sites page where the attackers have control.

According to Huntress, that page resembled the appearance of a Cloudflare verification page. However, instead of performing a standard security check, the page instructed users to execute a command on their computers. This method is called the ClickFix approach of social engineering. It depends on users performing an action themselves rather than simply downloading a file.

ClickFix starts a multi-stage malware chain

The fake verification page launched the next stage of the attack. Victims followed instructions that caused PowerShell to run on their Windows systems. The PowerShell stage downloaded a malicious MSI installer. The installer then used DLL sideloading to load harmful code through a legitimate signed application.

The Huntress team discovered two persistence techniques the criminals utilized in the infection chain. The malware laid out a Windows Run entry and a scheduled task to retain its access. The first version abused a Canon-signed executable & the updated version used a Stardock-signed executable. The adaptation is a clear indication of how the attacks evolve, replacing trustworthy elements while keeping the main methodology untouched.

The campaign also used several hiding techniques. One payload concealed its loader inside a WAV file. Another stage later used a NuGet package for delivery.

The malware also removed the Mark-of-the-Web security marker. Windows normally uses that marker to identify files downloaded from the internet. Removing it can reduce some security warnings linked to downloaded content. As a result, the attackers added another layer to the delivery process.

The final payload functions as a RAT. It can provide access to the screen, camera, microphone, files, and system information of a victim. It can also support additional payload execution. This gives attackers several options after they establish a foothold.

Huntress said its security team responded to at least 40 incidents connected to the infrastructure of the campaign. However, researchers confirmed that only two of those incidents began through malicious Custom GPTs. That distinction matters because the wider campaign did not depend entirely on ChatGPT. The Custom GPT acted as one entry point within a broader malware operation.

Huntress reported the first malicious GPT to OpenAI. OpenAI removed that GPT by September 25. Two days later, researchers found another Custom GPT connected to the same campaign. The implication here is that the attackers were flexible in changing their delivery methods. This means that removing a single fake site did not put an end to the attack.

In this case, the attackers also utilized reliable online services for success in social engineering tasks. Other recent attacks have also abused legitimate services and devices at scale, including Google shutting down a massive proxy network abusing millions of Android phones. It was not necessary for the attackers to make any fake ChatGPT websites at this stage since they used a legitimate service and hid their malicious plans there.

They then moved victims to another trusted service before delivering malware. Google Sites played a similar role in the next stage. The fake Cloudflare page added another familiar brand to the chain.

AI platforms become part of the social engineering problem

The situation indicates a new challenge for individuals using AI tools for accessing software and data. A malicious Custom GPT can look convincing while still operating under a legitimate service.

According to Huntress, it is evident that attackers are using reliable services with an eye on their social engineering jobs. They aim to lower the likelihood of the target suspecting malicious actions before getting to the malware stage.

The campaign also shows how attackers can combine several trusted services. In this incident, the actors included Google search, ChatGPT, Google Sites, and Cloudflare elements. But users must not consider familiar sites and interfaces as evidence for the safety of their activities. Commands like PowerShell execution or placement of some commands in the terminal should be especially doubtful.

OpenAI continues to release security and safety research in relation to increasingly efficient AI systems. Its recent safety work also shows that AI platforms face broader security challenges as their capabilities and uses expand.

For now, Huntress has confirmed two infections that specifically started through malicious Custom GPTs. Though the larger operation included at least 40 associated incidents, the researchers did not indicate whether all cases employed the same base of entries. Nevertheless, the lesson is simple: a reliable platform may become embroiled in an attack if adversaries know how to trick people into using it.

Share this article

About the Author

Kinyua Njeri is a journalist, blogger, and freelance writer. He’s a technology geek but mainly an internet privacy and freedom advocate. He has an unquenchable nose for news and loves sharing useful information with his readers. When not writing, Kinyua plays and coaches handball. He loves his pets!

More from Kinyua Njeri (Sam Kin)

Comments

No comments.