Threat actors are increasingly leveraging the capabilities of ChatGPT’s Custom GPTs to disguise malicious software as legitimate offerings. According to cybersecurity firm Huntress, these attackers are directing unsuspecting users to harmful sites using ClickFix tactics, ultimately deploying Remote Access Trojans (RATs). This development, observed in late September 2026, highlights the exploitation of trusted AI platforms for malicious ends.
Understanding Custom GPTs and Their Misuse
Custom GPTs allow users to tailor ChatGPT to perform specific tasks by uploading reference files and defining instructions. While designed to enhance user experience, these features are being misused by cybercriminals. Victims engaging with attacker-created Custom GPTs receive messages containing links to Google Sites, which lead to ClickFix-style attacks that initiate malware downloads.
In these incidents, victims are tricked into downloading a malicious MSI installer via a deceptive notification. This installer uses a DLL sideloading chain to load harmful shellcode, launching a persistence script and RAT payload. Over 40 individuals have reportedly been affected by this campaign.
Mechanism of the Attack
The attack begins with sponsored search results for terms like “chatgpt,” leading users to interact with a Custom GPT named “Plus 5.6.” Users are shown a “Service Availability Notice,” urging them to navigate to a backup Google Sites domain due to purported limitations on the primary site. This redirection employs a fake Cloudflare CAPTCHA, prompting users to execute a PowerShell command that installs malware.
The malicious installer abuses a legitimate Canon-signed binary to sideload a corrupted DLL, which extracts a loader hidden in a .WAV file. This loader then unpacks the trojan, bypassing security mechanisms and conducting anti-virtual machine checks. The trojan is capable of various actions, including stealing data, running remote desktop sessions, and deploying additional malware.
Broader Implications and Future Outlook
These findings are part of a broader trend of exploiting trusted platforms for cyberattacks. Similar ClickFix campaigns involve phishing sites that mimic trusted services like OpenAI Codex and Anthropic Claude to distribute malware. These campaigns often use malvertising and phishing emails to lure victims to malicious domains, leveraging sophisticated techniques like EtherHiding to evade detection.
The persistent abuse of AI platforms and other trusted services for cybercrime underscores the need for enhanced security measures. As threat actors continue to evolve their tactics, organizations must remain vigilant and adopt proactive defenses to protect their systems and users from such sophisticated attacks.
Overall, the misuse of Custom GPTs and ClickFix techniques highlights the challenges of securing AI technologies against sophisticated cyber threats. Stakeholders are urged to stay informed and implement robust security protocols to mitigate the risks posed by these emerging threats.
