5 Sources
[1]
This new ChatGPT scam tricks you into installing malware - how to spot the trap - ZDNET
* There's a new scam involving ChatGPT. * The scam starts with a sponsored Google link. * The link leads to a custom GPT that gives malicious information. A new scam involving ChatGPT has emerged, and it might lead you to install malware on your computer if you're not careful. Over the past
[2]
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. The threat actor is abusing the legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for
[3]
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another
[4]
A real ChatGPT page is being used to trick people into installing malware
That command could install malware that could access files, the screen, the webcam, the microphone, and more. There was a time when spotting a sketchy download meant looking for misspelled websites, strange pop-ups, and other obvious red flags. But that gets much harder when the scam starts on a
[5]
Hackers host fake ChatGPT model on its official website -- but really it's just malware
* Attackers abused custom ChatGPT bots and Google Sites to deliver ClickFix malware * Fake troubleshooting prompts tricked victims into executing malicious commands * Campaign shows trusted AI platforms increasingly leveraged in social engineering attacks Criminals are using custom GPTs in
Share
Copy Link
Cybersecurity researchers at Huntress discovered attackers abusing ChatGPT's Custom GPT feature to distribute malware through sponsored Google links. The scam uses a fake model called Plus 5.6 hosted on the legitimate ChatGPT.com domain, directing victims to malicious Google Sites pages with fake Cloudflare checks that deploy remote access trojan malware via PowerShell commands.
Cybersecurity researchers at Huntress have uncovered a sophisticated ChatGPT scam that exploits the platform's Custom GPT feature to distribute malware
2
. The campaign affected dozens of users, with investigators responding to at least 40 incidents connected to the malicious infrastructure5
. Attackers created a malicious custom GPT named Plus 5.6, designed to mimic OpenAI's official model naming conventions like GPT-3.5 and GPT-5 Pro5
. What makes this social engineering attack particularly dangerous is that Custom GPTs are hosted on the legitimate ChatGPT.com domain, lending immediate credibility to the operation and increasing the likelihood victims will follow malicious instructions2
.
Source: BleepingComputer
The attack begins when users search for ChatGPT on Google and click on sponsored Google links that appear above authentic search results
1
. Once victims interact with the Plus 5.6 Custom GPT, they receive a Service Availability Notice regardless of what they type, claiming limited availability on the primary domain3
. The message presents two options: upgrade to a Plus subscription or navigate to a backup domain, with the notice recommending immediate access through the backup option3
. This backup domain is hosted on Google Sites, another trusted platform that attackers leverage to appear legitimate2
. The Google Sites page displays fake Cloudflare checks that employ ClickFix attacks, deceiving users into copying and executing malicious PowerShell commands in Windows3
. Roman Oliinyk, CEO of PayCore Media, Inc., emphasized that a real Cloudflare check would never ask users to do anything on their keyboard beyond checking a box or pressing a button1
.
Source: ZDNet
Executing the PowerShell command initiates installing malware through a malicious MSI installer that launches a legitimate, signed application and a modified DLL loading the payload
2
. The payload is a remote access trojan with extensive capabilities including remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads2
. The RAT malware can view screens, search files, use webcams and microphones, capture system audio, and install more malware4
. It documents installed antivirus software, Microsoft Defender status, and system profiles while recognizing 17 web browsers and launching the default one3
. For persistence, the malware creates a new Run key in the Windows Registry and a scheduled task, both named Canon Configuration Reader2
.Related Stories
The attack chain demonstrates sophisticated technical implementation across multiple stages. Huntress researchers highlighted phase 6, noting attackers built a custom encrypted file system to conceal the persistence script and RAT malware
2
. Instead of one encrypted blob, it's a custom archive with its own folder tree, essentially a homemade encrypted zip file starting with a small header, followed by an index of 1,128 entries recording parent folders, sizes, and per-file keys, with file contents packed consecutively2
. The RAT uses DNS-over-HTTPS through Cloudflare, Google, and Quad9 servers to find its command-and-control server, with lookups traveling inside ordinary HTTPS traffic to well-known resolvers so they never appear in local DNS logs3
. The loader shellcode bypasses AMSI, unhooks ntdll.dll to sidestep user-mode monitoring by security programs, and runs anti-virtual machine checks by examining CPU vendor strings against various VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services3
.
Source: Hacker News
OpenAI took down the first malicious custom GPT by September 25, but researchers discovered a second GPT linked to the same campaign on September 27 that remained active when they published their report
2
. More recent attacks switched from a Canon-signed host application to a Stardock-signed one and changed how they concealed and delivered the loader, although the payload remained the same2
. OpenAI plans to retire Custom GPTs on December 112
. The campaign represents part of a broader trend where threat actors continue turning trusted platforms into convincing entry points for social engineering attacks, whether via ChatGPT's Custom GPT feature or through Google Sites for hosting ClickFix attacks3
. Most of the infection chain runs in memory or is supported by files that appear benign, allowing defenders to implement detections based on process activity monitoring2
. Users should type ChatGPT.com directly into browsers instead of searching for it, avoid clicking sponsored Google links, and never paste and run commands on computers unless certain of their function1
.Summarized by
Navi
[2]
[4]
11 Dec 2025•Technology

09 Jun 2026•Technology

04 Jul 2025•Technology
