Malware · 3h ago
Huntress found attackers abusing ChatGPT Custom GPT pages starting in late September, with at least 40 incidents tied to one Google Sites domain and a second Custom GPT appearing after OpenAI took down the first.
The attacker-built GPT answered with a link on a real ChatGPT.com page, so the victim stayed inside a trusted-looking interface before landing on a ClickFix lure. That chain led to a malicious MSI installer, then a Canon-signed program was abused to sideload a DLL and slip past simple detection.
The lasting problem is platform trust: if staff use AI assistants that can publish pages or share links, reputation filters and URL blocking may miss lures that start on an approved service and can be recreated quickly after takedown.
3 sources covering this story
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.
Malicious Custom GPT on chatgpt.com lures users into installing a RAT - Help Net Security
Malware peddlers are using sponsored Google results to push a malicious ChatGPT Custom GPT named "Plus 5.6".
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix | Huntress
Huntress researchers reveal how attackers are exploiting ChatGPT Custom GPTs to spread ClickFix lures and DLL-sideloaded malware.
Part of the PlainSec briefing for 2026-09-29