Hackers exploit ChatGPT custom GPTs to launch ClickFix social engineering attacks

1 week ago 4



Someone finally figured out how to weaponize the custom GPT feature that OpenAI launched to much fanfare. Researchers at Huntress uncovered a campaign in late September 2026 where attackers created malicious Custom GPTs on chatgpt.com, using the trusted OpenAI domain as the opening move in a multi-stage malware attack. The scheme is elegant in a way that should make security teams nervous. Victims interacted with what appeared to be a legitimate custom AI assistant, only to be redirected through a chain that ended with a full-featured remote access trojan sitting on their machine. How the attack works The attackers built personalized GPT instances with innocuous-sounding names. One was called “Plus 5.6.” These custom GPTs were designed to steer conversations toward actions that ultimately sent victims to a Google Sites page masquerading as a Cloudflare CAPTCHA verification. The fake CAPTCHA page prompted users to execute a PowerShell command. That single action kicked off an eight-stage ClickFix infection chain. The PowerShell command fetched a malicious MSI installer, which in turn deployed a remote access trojan with a concerning feature set: remote desktop control, audio and vid...

Read Entire Article