Threat actors have found another way to turn a legitimate online service into part of a malware delivery chain. This time, they abused custom versions of ChatGPT to impersonate an official OpenAI offering and steer victims toward a ClickFix attack that ultimately installed a remote access trojan, or RAT, a type of malware that lets an attacker remotely control or interact with an infected computer.
The campaign was documented by Huntress and reported by BleepingComputer. What makes this attack notable is that the first page a victim encountered could be hosted on the legitimate ChatGPT website. The malicious software was not being delivered directly by ChatGPT. Instead, attackers used a custom GPT as the trusted-looking first step in a social-engineering chain.
What is a custom GPT?
A custom GPT is a version of ChatGPT configured for a particular purpose. A builder can give it its own name and instructions, provide reference material or knowledge files, and enable selected tools or capabilities. The result can behave like a specialized assistant while still running inside ChatGPT.
That flexibility is useful for legitimate purposes, but it also gives criminals another surface to abuse. A malicious builder does not need to compromise OpenAI itself to create something that looks convincing. If the GPT is hosted on the real ChatGPT domain and is given a name that sounds official, an unfamiliar user may assume it is an OpenAI product.
OpenAI has already announced plans to retire custom GPTs across ChatGPT plans and move these workflows toward plugins. The standard retirement date is December 11, 2026, although OpenAI says timing can vary by plan or workspace and some qualifying workspaces may have a later date. That retirement is a separate product transition and should not be interpreted as a response to this malware campaign.
The fake ‘Plus 5.6’ GPT
According to Huntress, attackers created a custom GPT named ‘Plus 5.6.’ The name was chosen to resemble an official ChatGPT model or subscription offering. Huntress noted that the page identified the GPT as being made by a ‘community builder,’ but someone who did not understand how custom GPTs work could easily mistake the page for a normal ChatGPT experience.
Some victims reportedly reached the malicious GPT after searching Google for ChatGPT and clicking a sponsored result. That is an important part of the attack: the victim was not necessarily following a strange link from an unsolicited email. A paid search result could lead to a page on the legitimate ChatGPT domain, providing two layers of apparent credibility before anything obviously malicious happened.
When a user interacted with the malicious GPT, it returned a supposed service availability notice. It claimed that the primary service had limited availability and offered a ‘backup domain’ hosted through Google Sites.
Then comes ClickFix
The Google Sites page presented a fake Cloudflare-style verification. Rather than performing a real CAPTCHA or browser verification, the page instructed the victim to copy and run a command in Windows PowerShell.
This is the technique commonly called ClickFix. Instead of exploiting a software vulnerability, the attacker convinces the user to perform the dangerous action. Fake CAPTCHA pages, error messages and troubleshooting instructions are frequently used to persuade victims to paste commands into PowerShell, Windows Run or a terminal.
A legitimate CAPTCHA should not require you to open PowerShell, Command Prompt, Windows Run or a terminal and paste a command. If a website asks you to do that in order to prove you are human, fix a browser problem, install an update or regain access to a service, stop.
What the malware did
Huntress found that the PowerShell command downloaded and executed an obfuscated script, which then installed a malicious MSI package, a Windows Installer package commonly used to install software. The infection chain also used DLL sideloading, a technique in which a legitimate application is tricked into loading a malicious DLL file, and established persistence so the malware could return after portions of it were removed.
The researchers described an unusually elaborate multi-stage chain ending in the RAT. It could collect information about the infected computer and provided capabilities for remote desktop access, screen capture, camera and microphone access, file searching and the execution of additional payloads.
Huntress said its security operations center responded to at least 40 incidents associated with the Google Sites domain used in the campaign. Two of those infections were confirmed to have originated through a custom GPT. After Huntress reported the first malicious GPT to OpenAI and it was removed, researchers later found another custom GPT associated with the same campaign.
The real lesson is trust
This campaign is another reminder that seeing a familiar domain does not automatically make every piece of content hosted there trustworthy. ChatGPT, Google Sites and other legitimate platforms can be abused as links in a social-engineering chain without those platforms themselves being compromised.
The name of an AI assistant deserves scrutiny as well. A custom GPT called ‘Plus 5.6,’ ‘Support,’ ‘Security Update’ or anything else is not automatically an official OpenAI service simply because it appears on ChatGPT. Look at who created it, why you reached it and what it is asking you to do.
Sponsored search results deserve similar caution. Advertising placement means someone paid to place a result prominently; it is not a security endorsement. When looking for ChatGPT or another well-known service, verify that you are using the provider’s official service rather than assuming the first advertisement is the right destination.
What users should remember
- Do not run PowerShell, Command Prompt, Windows Run or terminal commands supplied by a CAPTCHA or unexpected website.
- Do not assume a page is trustworthy solely because it is hosted on ChatGPT, Google Sites or another familiar service.
- Check whether a GPT is presented as an official OpenAI product or as something created by a community builder.
- Be cautious with sponsored search results, especially when looking for software downloads, account upgrades or support.
- If a website claims a service is unavailable and sends you to a ‘backup’ site, verify the claim independently through the service’s official site.
AI services are becoming another trusted surface that attackers can imitate or misuse. The technology behind this campaign is interesting, but the first compromise still depends on a familiar security problem: persuading a person to trust the wrong thing and execute the attacker’s instructions.
Sources
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Malicious custom GPTs abuse ChatGPT trust to spread RAT malware
Threat actors have found another way to turn a legitimate online service into part of a malware delivery chain. This time, they abused custom versions of ChatGPT to impersonate an official OpenAI offering and steer victims toward a ClickFix attack that ultimately installed a remote access trojan, or RAT, a type of malware that lets an attacker remotely control or interact with an infected computer.
The campaign was documented by Huntress and reported by BleepingComputer. What makes this attack notable is that the first page a victim encountered could be hosted on the legitimate ChatGPT website. The malicious software was not being delivered directly by ChatGPT. Instead, attackers used a custom GPT as the trusted-looking first step in a social-engineering chain.
What is a custom GPT?
A custom GPT is a version of ChatGPT configured for a particular purpose. A builder can give it its own name and instructions, provide reference material or knowledge files, and enable selected tools or capabilities. The result can behave like a specialized assistant while still running inside ChatGPT.
That flexibility is useful for legitimate purposes, but it also gives criminals another surface to abuse. A malicious builder does not need to compromise OpenAI itself to create something that looks convincing. If the GPT is hosted on the real ChatGPT domain and is given a name that sounds official, an unfamiliar user may assume it is an OpenAI product.
OpenAI has already announced plans to retire custom GPTs across ChatGPT plans and move these workflows toward plugins. The standard retirement date is December 11, 2026, although OpenAI says timing can vary by plan or workspace and some qualifying workspaces may have a later date. That retirement is a separate product transition and should not be interpreted as a response to this malware campaign.
The fake ‘Plus 5.6’ GPT
According to Huntress, attackers created a custom GPT named ‘Plus 5.6.’ The name was chosen to resemble an official ChatGPT model or subscription offering. Huntress noted that the page identified the GPT as being made by a ‘community builder,’ but someone who did not understand how custom GPTs work could easily mistake the page for a normal ChatGPT experience.
Some victims reportedly reached the malicious GPT after searching Google for ChatGPT and clicking a sponsored result. That is an important part of the attack: the victim was not necessarily following a strange link from an unsolicited email. A paid search result could lead to a page on the legitimate ChatGPT domain, providing two layers of apparent credibility before anything obviously malicious happened.
When a user interacted with the malicious GPT, it returned a supposed service availability notice. It claimed that the primary service had limited availability and offered a ‘backup domain’ hosted through Google Sites.
Then comes ClickFix
The Google Sites page presented a fake Cloudflare-style verification. Rather than performing a real CAPTCHA or browser verification, the page instructed the victim to copy and run a command in Windows PowerShell.
This is the technique commonly called ClickFix. Instead of exploiting a software vulnerability, the attacker convinces the user to perform the dangerous action. Fake CAPTCHA pages, error messages and troubleshooting instructions are frequently used to persuade victims to paste commands into PowerShell, Windows Run or a terminal.
A legitimate CAPTCHA should not require you to open PowerShell, Command Prompt, Windows Run or a terminal and paste a command. If a website asks you to do that in order to prove you are human, fix a browser problem, install an update or regain access to a service, stop.
What the malware did
Huntress found that the PowerShell command downloaded and executed an obfuscated script, which then installed a malicious MSI package, a Windows Installer package commonly used to install software. The infection chain also used DLL sideloading, a technique in which a legitimate application is tricked into loading a malicious DLL file, and established persistence so the malware could return after portions of it were removed.
The researchers described an unusually elaborate multi-stage chain ending in the RAT. It could collect information about the infected computer and provided capabilities for remote desktop access, screen capture, camera and microphone access, file searching and the execution of additional payloads.
Huntress said its security operations center responded to at least 40 incidents associated with the Google Sites domain used in the campaign. Two of those infections were confirmed to have originated through a custom GPT. After Huntress reported the first malicious GPT to OpenAI and it was removed, researchers later found another custom GPT associated with the same campaign.
The real lesson is trust
This campaign is another reminder that seeing a familiar domain does not automatically make every piece of content hosted there trustworthy. ChatGPT, Google Sites and other legitimate platforms can be abused as links in a social-engineering chain without those platforms themselves being compromised.
The name of an AI assistant deserves scrutiny as well. A custom GPT called ‘Plus 5.6,’ ‘Support,’ ‘Security Update’ or anything else is not automatically an official OpenAI service simply because it appears on ChatGPT. Look at who created it, why you reached it and what it is asking you to do.
Sponsored search results deserve similar caution. Advertising placement means someone paid to place a result prominently; it is not a security endorsement. When looking for ChatGPT or another well-known service, verify that you are using the provider’s official service rather than assuming the first advertisement is the right destination.
What users should remember
AI services are becoming another trusted surface that attackers can imitate or misuse. The technology behind this campaign is interesting, but the first compromise still depends on a familiar security problem: persuading a person to trust the wrong thing and execute the attacker’s instructions.
Sources
Share this:
Like this:
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Published in article commentary