Skull on screen showing custom GPT and malware

Hackers Abuse Custom GPT Instances on chatgpt.com to Distribute ClickFix Malware

Hackers are leveraging custom GPT models to deliver malware to unsuspecting users by redirecting them to a malicious website hosted on a backup Google Sites domain.

The attackers exploit OpenAI’s custom GPTs, which allow users to build and publish personalized versions tailored for a particular purpose, such as customer support. However, OpenAI intends to retire the feature by December 11, 2026.

Custom GPT models deliver malware

The infection chain starts when users search “chatgpt” on Google. The search returns a sponsored result leading to a custom GPT page on the legitimate ChatGPT domain. The custom GPT displays a message warning of “limited availability on the primary domain” and instructs users to upgrade their subscription or use the “backup domain” hosted on Google Sites.

However, the “backup domain” redirects them to a fake Cloudflare CAPTCHA check that delivers ClickFix malware. According to threat intelligence firm Huntress, the page prompts victims to execute a PowerShell command that deploys the primary payload. The executable is a Canon-signed MSI installer (ISOSimple.msi) that sideloads malicious DLL files, including some legitimately signed Windows libraries.

“That command kicked off an eight-stage infection chain,” said John Bruggeman, vCISO, CBTS. “Not two or three hops, which is normal for this kind of attack. Eight.”

The DLL file is capable of remote desktop access, file searching, audio and camera capture, reconnaissance, and deploying additional malware. It also creates a User Run key and a scheduled task named Canon that reappears after deletion, which is typical malware behavior.

The DLL also loads a .wav file that unpacks an encrypted remote access trojan (RAT) monitor.raw, a virtual file system containing 315 folders and 806 files. Cybercriminals have previously packed malware, including info stealers like Lumma Stealer, in .wav, .mp3, .png, and .mp4 files, behind a PureCrypter layer.

“Instead of one encrypted blob, it’s a custom archive with its own folder tree, basically a homemade, encrypted zip file,” the researchers explained.

However, most files are harmless, and most infections occur in memory without saving to disk, further complicating detection and making process monitoring the most reliable method.

After execution, the RAT takes inventory of the host computer by checking installed antivirus software, Microsoft Defender status, domain details, open ports, network adapters, installed software, activated Windows features, and hardware fingerprints.

Interestingly, Windows Defender has previously quarantined ISOSimple.msi after identifying it as a Trojan. However, by the time of detection, the infection chain had already started, and the malware had created persistence.

“The workflow for this attack was not some slapped-together AI slop, it was sophisticated,” Bruggeman added. “The lure of the Custom GPT domain got the victims to paste a PowerShell command into their own machine.”

Google Sites and custom GPTs used to deliver malware

Huntress has responded to about 40 cases involving malicious Google Sites domains, with two originating from custom GPT instances. The attackers named one of the malicious custom GPT instances “Plus 5.6” to mimic an official release and gain user trust.

“The campaign has impacted dozens of users: the Huntress SOC has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance,” the researchers stated.

Meanwhile, the threat intelligence firm has notified OpenAI, which responded by removing the custom GPT instance by September 25. However, by September 27, another custom GPT had resurfaced.