Threat actors are using custom variants of OpenAI's ChatGPT promoted in sponsored Google results to direct users to malicious sites. These sites use ClickFix attacks to deliver malware.
The threat actor abuses a legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task. OpenAI hosts these custom GPTs, which can be published for others to install and use. OpenAI plans to retire custom GPTs on December 11.
Researchers uncovered custom GPT malware
Managed detection and response company Huntress identified the malicious campaign, which affected dozens of users. The threat actor named the malicious GPT model Plus 5.6. The model directs users to an alleged backup site hosted on Google Sites.
The page shows a fake Cloudflare check and instructs visitors to run a PowerShell command. This command deploys the infection chain. Huntress previously observed attacks using deceptive ChatGPT conversations to launch ClickFix ruses, but using custom GPTs is a novel approach.

Malicious instructions leverage trusted domains
The malicious instructions are hosted on the legitimate ChatGPT.com domain in both attacks. This lends legitimacy to the operation and increases the chances victims will follow the instructions.
If executed locally, the PowerShell command installs a malicious MSI. This MSI launches a legitimate, signed application and a modified DLL loading the malware.
Read nextUK AI Security Institute warns GPT-6 Astra excels at supply chain attacksAttackers deployed a remote access trojan
The payload is a remote access trojan with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads. For persistence, the malware creates a new Run key in the Windows Registry and a scheduled task named Canon Configuration Reader.
Huntress investigated at least 40 incidents connecting to the Google Sites page. The firm confirmed that only two involved a custom GPT variant. OpenAI took down the first GPT by September 25. Researchers found a second GPT linked to the same campaign on September 27, which was still active when they published their report.
More recent attacks switched from a Canon-signed host application to a Stardock-signed one and changed how it concealed and delivered the loader, though the payload remained the same. Huntress highlights phase six of the multi-stage attack chain, noting that attackers built a custom encrypted file system to conceal the persistence script and RAT.
Huntress says most of the infection chain runs in memory or is supported by files that appear benign. The researchers provide detection opportunities, including PowerShell pinging msiexec.exe to silently launch an MSI installer from the temporary folder. Additional signs of compromise include a signed app starting from an unusual folder under local app data programs, and a matching Run value and scheduled task that reappear if deleted.



