Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit ChatGPT in New ClickFix Cyber Attacks

Hackers Exploit ChatGPT in New ClickFix Cyber Attacks

Posted on September 29, 2026 By CWS

Cybersecurity experts have uncovered a new wave of ClickFix attacks utilizing ChatGPT Custom GPTs to mislead victims into executing harmful software on their devices. These targeted attacks involve impersonating legitimate products to deceive users into downloading malware.

Understanding Custom GPTs in Cyber Attacks

Custom GPTs are tailored versions of ChatGPT, designed with specific instructions and features. Hosted on ChatGPT.com, these tools display custom names and the creator’s profile at the top of their pages. This personalization is being exploited by cybercriminals to enhance their phishing schemes.

In recent incidents reported by cybersecurity firm Huntress, threat actors have programmed Custom GPTs to direct users to a Google Sites link, which subsequently leads to a ClickFix page. Victims on this page are instructed to run PowerShell commands, triggering the download of a malicious MSI file, part of a complex infection chain.

Details of the Malicious Campaign

Huntress reports that the campaign has already compromised at least 40 users, with two incidents directly linked to the fraudulent Custom GPTs. While OpenAI acted to remove one of these GPTs on September 25, another was identified two days later, indicating ongoing efforts by attackers to exploit this method.

The attackers deceived users by naming the Custom GPT “Plus 5.6” and suggesting it was a product from a reputable community builder. The ruse included a fake notification about limited availability, urging users to upgrade or access the service through a backup domain.

Technical Analysis of the Attack

The fraudulent backup domain, hosted on a Google Sites page, included a Cloudflare CAPTCHA check as part of the ClickFix attack strategy. This was aimed at convincing victims to execute PowerShell scripts that installed a malicious application. The initial installer misused a Canon-signed application for DLL sideloading to maintain persistence through a User Run key and a scheduled task disguised as “Canon Configuration Reader.”

Subsequent stages of the attack involved a loader masked as an audio file to avoid detection, executing system checks, and creating a fake loading screen. Ultimately, the attack leveraged a heavily obfuscated audio file containing a custom archive with numerous folders and files, culminating in a RAT capable of executing various payloads.

Although the payload delivered by the second Custom GPT remained the same, the threat actor switched to using a Stardock executable and a patched Stardock DLL for infection, embedding the loader within a Microsoft NuGet package instead of an audio file.

In conclusion, these sophisticated attacks underscore the evolving tactics of cybercriminals and the need for robust security measures to protect against such threats. As hackers continue to innovate their methods, vigilance and timely response by cybersecurity firms and platforms like OpenAI are crucial in mitigating these risks.

Security Week News Tags:ChatGPT, ClickFix, Custom GPTs, cyber attack, Cybersecurity, Hacking, Malware, OpenAI, PowerShell, Threat Actors

Post navigation

Previous Post: AgtaBackup RAT Exploits Fake Microsoft Store to Infiltrate PCs
Next Post: Modulate Secures $25M to Combat Deepfake Audio Threats

Related Posts

CrowdStrike to Acquire Pangea to Launch AI Detection and Response (AIDR) CrowdStrike to Acquire Pangea to Launch AI Detection and Response (AIDR) Security Week News
Is the Traditional SOC Outdated in AI Era? Is the Traditional SOC Outdated in AI Era? Security Week News
Gladinet CentreStack Flaw Exploited to Hack Organizations Gladinet CentreStack Flaw Exploited to Hack Organizations Security Week News
June 2026 Cybersecurity M&A: 37 Key Deals Unveiled June 2026 Cybersecurity M&A: 37 Key Deals Unveiled Security Week News
Straiker Secures M to Enhance AI Security Solutions Straiker Secures $64M to Enhance AI Security Solutions Security Week News
Stragglers From Myanmar Scam Center Raided by Army Cross Into Thailand as Buildings are Blown Up Stragglers From Myanmar Scam Center Raided by Army Cross Into Thailand as Buildings are Blown Up Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Modulate Secures $25M to Combat Deepfake Audio Threats
  • Hackers Exploit ChatGPT in New ClickFix Cyber Attacks
  • AgtaBackup RAT Exploits Fake Microsoft Store to Infiltrate PCs
  • Rig Security Secures $12M to Combat AI Identity Threats
  • BotHelper RAT Exploits Encrypted Payloads for Windows Surveillance

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Modulate Secures $25M to Combat Deepfake Audio Threats
  • Hackers Exploit ChatGPT in New ClickFix Cyber Attacks
  • AgtaBackup RAT Exploits Fake Microsoft Store to Infiltrate PCs
  • Rig Security Secures $12M to Combat AI Identity Threats
  • BotHelper RAT Exploits Encrypted Payloads for Windows Surveillance

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark