Malware · 3h ago

ChatGPT Custom GPTs Carried ClickFix Lures

Huntress found attackers abusing ChatGPT Custom GPT pages starting in late September, with at least 40 incidents tied to one Google Sites domain and a second Custom GPT appearing after OpenAI took down the first.

The attacker-built GPT answered with a link on a real ChatGPT.com page, so the victim stayed inside a trusted-looking interface before landing on a ClickFix lure. That chain led to a malicious MSI installer, then a Canon-signed program was abused to sideload a DLL and slip past simple detection.

The lasting problem is platform trust: if staff use AI assistants that can publish pages or share links, reputation filters and URL blocking may miss lures that start on an approved service and can be recreated quickly after takedown.

Timeline

Sources

3 sources covering this story

Part of the PlainSec briefing for 2026-09-29

Editions

Related stories