Threat actors exploit ChatGPT Custom GPTs to deliver malware via ClickFix lures, infecting over 40 users

Published:

In a concerning development, threat actors have been exploiting ChatGPT Custom GPTs to deliver malware through ClickFix lures, infecting over 40 users. This activity, observed by Huntress in late September 2026, highlights the ongoing misuse of trusted artificial intelligence platforms for malicious purposes. Previous campaigns have similarly weaponized AI tools to distribute various types of malware, including remote access trojans (RATs) and information stealers.

Mechanism of Attack

Custom GPTs allow users to create personalized versions of ChatGPT, enabling them to define specific instructions and upload reference files. However, attackers have manipulated this feature to create a Custom GPT that interacts with victims, directing them to malicious links hosted on Google Sites. According to Huntress, victims were led to a ClickFix-style attack that initiated the download of a malicious MSI installer.

The attack begins with a sponsored search result for “chatgpt” on Google, where two Custom GPT links are presented. Users who engage with the Custom GPT named “Plus 5.6” receive a “Service Availability Notice,” prompting them to either upgrade their subscription or navigate to a backup Google Sites domain due to “limited availability.” This notice encourages users to opt for the backup domain, which then presents a fake CAPTCHA check that triggers the ClickFix attack.

Malware Delivery and Functionality

The malicious PowerShell command executed during the ClickFix attack deploys an MSI installer, which abuses a legitimate Canon-signed binary to sideload a rogue DLL. This DLL is designed to load a second, unsigned DLL that extracts an encrypted loader from a WAV audio file. The loader then unpacks the trojan and a persistence script while employing various evasion techniques to bypass security measures.

The RAT, once deployed, boasts a range of capabilities, including:

  • Documenting installed antivirus software and system profiles.
  • Running remote desktop sessions and broadcasting screen activity.
  • Capturing input from the endpoint’s camera and microphone.
  • Recognizing and launching web browsers.
  • Searching file contents across the system.
  • Dropping and executing secondary payloads and scripts.

Huntress noted that the RAT uses DNS-over-HTTPS to communicate with its command and control (C2) server, obscuring its traffic within ordinary HTTPS requests to avoid detection in local DNS logs. The malware has been found to drop a legitimate binary that launches Google Chrome with a temporary profile, further complicating detection efforts.

Broader Implications and Ongoing Threats

This incident is part of a larger trend where threat actors are increasingly leveraging trusted platforms for social engineering attacks. Huntress emphasized that the use of ChatGPT’s Custom GPT feature and Google Sites for hosting ClickFix attacks demonstrates a shift in tactics aimed at exploiting user trust in legitimate services.

Additionally, multiple ClickFix-oriented campaigns have been identified, utilizing phishing websites and compromised domains to distribute malware. These campaigns have targeted various sectors, including government systems, and have been linked to organized cybercrime groups.

As the landscape of cyber threats continues to evolve, organizations must remain vigilant and implement robust security measures to protect against such sophisticated attacks. The exploitation of AI platforms underscores the need for continuous monitoring and adaptive defense strategies to mitigate risks associated with emerging technologies.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

OpenAI disrupts alleged distillation attack by Chinese rival Moonshot AI

OpenAI has reported the disruption of a "coordinated campaign" aimed at extracting reasoning capabilities from its AI models, attributing the activity to a Chinese...

Microsoft Ignite 2026 to focus on AI-driven security solutions and strategies

Microsoft Ignite 2026 is set to emphasize AI-driven security solutions, reflecting the growing integration of artificial intelligence in cybersecurity practices. Scheduled for November 17-20,...

Ukrainian researchers warn of mobile malware targeting military and government officials

Ukrainian researchers have issued a warning regarding a surge in mobile malware targeting military personnel and government officials, as detailed in a report from...

Star Blizzard evolves phishing tactics with new RedFlick malware delivery technique

In a significant evolution of its cyber operations, the Russian state-sponsored threat actor known as Star Blizzard has refined its phishing tactics and malware...