VYPR
researchPublished Sep 29, 2026· 3 sources

Hackers Weaponize ChatGPT Custom GPTs for Malware Distribution

Threat actors are exploiting OpenAI's Custom GPT feature to impersonate AI tools and trick users into downloading malware, including a sophisticated remote access trojan.

Cybercriminals are actively abusing OpenAI's Custom GPT feature, transforming it into a potent tool for distributing malware. Researchers have identified a campaign where attackers create seemingly legitimate AI tools within ChatGPT's ecosystem to lure unsuspecting users into downloading malicious software, most notably a sophisticated remote access trojan (RAT).

The attack chain, dubbed "ClickFix" by researchers, begins with malvertising and fake verification prompts. Users searching for "ChatGPT" might encounter a sponsored search result leading to a convincing fake "chatgpt.com" domain. This redirects them to a Google Sites page designed to mimic a legitimate ChatGPT interface, often impersonating official models like "Plus 5.6." The lure then presents a "Service Availability Notice," directing users to a supposed backup site.

This backup site is another Google Sites page, masquerading as a ChatGPT and Cloudflare CAPTCHA verification screen. Instead of a genuine verification process, victims are prompted to execute a PowerShell command. This social engineering tactic exploits users' willingness to resolve perceived minor issues or complete verification steps, tricking them into running malicious code themselves. The command downloads an obfuscated PowerShell script that fetches and silently installs a malicious MSI package.

The MSI package, disguised as "Advanced Printer Configuration Reader," hides itself from standard program listings and installs in the user's AppData directory. It then leverages a legitimate, signed Canon executable (COTFileReadApp.exe) to perform DLL sideloading. This technique involves the legitimate program loading a malicious DLL from the same directory, allowing the malware to execute with the privileges of the signed application.

Further stages involve a custom loader that implements advanced evasion techniques, including an AMSI bypass, ntdll unhooking, and anti-virtual machine checks. This loader then extracts and executes encrypted malware code from a concealed archive. The final payload is a potent RAT capable of remote desktop access, capturing microphone and camera feeds, searching files, executing arbitrary code, and maintaining persistence through scheduled tasks and registry run keys.

Researchers have observed at least 40 incidents utilizing this infrastructure, with attackers quickly adapting. Following OpenAI's removal of an initial malicious GPT, a replacement emerged within days, using a different signed executable but delivering the same RAT. This highlights the dynamic nature of these attacks and the attackers' ability to pivot to other legitimate signed binaries to evade detection.

Security experts advise users to be extremely cautious of any AI service or verification page that requests the execution of commands in PowerShell, Terminal, or the Run dialog. Legitimate verification processes do not require users to interact with command-line interfaces. Defenders should focus on behavioral detection, looking for anomalies such as signed binaries executing from unusual locations, unexpected DLL loading, and suspicious PowerShell activity, rather than relying solely on specific application names.

The malicious "Plus 5.6" Custom GPT, distributed via sponsored Google ads, directs users to a fake Cloudflare CAPTCHA page that prompts them to execute commands in their terminal. This leads to the sideloading of a RAT, with the Huntress SOC responding to at least 40 incidents linked to this specific campaign. While OpenAI removed the initial GPT, attackers quickly deployed another, demonstrating the evolving nature of this threat.

This new report details a specific campaign dubbed 'ClickFix' that leverages custom GPTs to impersonate legitimate software and lure users into executing malicious PowerShell commands. The campaign has been active since at least September 25, with at least two incidents linked to a custom GPT instance, and OpenAI has since taken down the malicious GPTs. The attackers have also evolved their tactics, switching from an audio file loader to a Microsoft NuGet package for the second discovered GPT instance.

Synthesized by Vypr AI