In a concerning development, threat actors have been exploiting ChatGPT Custom GPTs to deliver malware through ClickFix lures, infecting over 40 users. This activity, observed by Huntress in late September 2026, highlights the ongoing misuse of trusted artificial intelligence platforms for malicious purposes. Previous campaigns have similarly weaponized AI tools to distribute various types of malware, including remote access trojans (RATs) and information stealers.
Mechanism of Attack
Custom GPTs allow users to create personalized versions of ChatGPT, enabling them to define specific instructions and upload reference files. However, attackers have manipulated this feature to create a Custom GPT that interacts with victims, directing them to malicious links hosted on Google Sites. According to Huntress, victims were led to a ClickFix-style attack that initiated the download of a malicious MSI installer.
The attack begins with a sponsored search result for “chatgpt” on Google, where two Custom GPT links are presented. Users who engage with the Custom GPT named “Plus 5.6” receive a “Service Availability Notice,” prompting them to either upgrade their subscription or navigate to a backup Google Sites domain due to “limited availability.” This notice encourages users to opt for the backup domain, which then presents a fake CAPTCHA check that triggers the ClickFix attack.
Malware Delivery and Functionality
The malicious PowerShell command executed during the ClickFix attack deploys an MSI installer, which abuses a legitimate Canon-signed binary to sideload a rogue DLL. This DLL is designed to load a second, unsigned DLL that extracts an encrypted loader from a WAV audio file. The loader then unpacks the trojan and a persistence script while employing various evasion techniques to bypass security measures.
The RAT, once deployed, boasts a range of capabilities, including:
- Documenting installed antivirus software and system profiles.
- Running remote desktop sessions and broadcasting screen activity.
- Capturing input from the endpoint’s camera and microphone.
- Recognizing and launching web browsers.
- Searching file contents across the system.
- Dropping and executing secondary payloads and scripts.
Huntress noted that the RAT uses DNS-over-HTTPS to communicate with its command and control (C2) server, obscuring its traffic within ordinary HTTPS requests to avoid detection in local DNS logs. The malware has been found to drop a legitimate binary that launches Google Chrome with a temporary profile, further complicating detection efforts.
Broader Implications and Ongoing Threats
This incident is part of a larger trend where threat actors are increasingly leveraging trusted platforms for social engineering attacks. Huntress emphasized that the use of ChatGPT’s Custom GPT feature and Google Sites for hosting ClickFix attacks demonstrates a shift in tactics aimed at exploiting user trust in legitimate services.
Additionally, multiple ClickFix-oriented campaigns have been identified, utilizing phishing websites and compromised domains to distribute malware. These campaigns have targeted various sectors, including government systems, and have been linked to organized cybercrime groups.
As the landscape of cyber threats continues to evolve, organizations must remain vigilant and implement robust security measures to protect against such sophisticated attacks. The exploitation of AI platforms underscores the need for continuous monitoring and adaptive defense strategies to mitigate risks associated with emerging technologies.


