FoxTPNL / Wikimedia Commons (CC BY 4.0)
Hackers exploit ChatGPT custom GPTs to launch ClickFix social engineering attacks
Attackers built fake custom GPTs on OpenAI's platform to funnel victims into an eight-stage malware infection chain, researchers found
Someone finally figured out how to weaponize the custom GPT feature that OpenAI launched to much fanfare. Researchers at Huntress uncovered a campaign in late September 2026 where attackers created malicious Custom GPTs on chatgpt.com, using the trusted OpenAI domain as the opening move in a multi-stage malware attack.
The scheme is elegant in a way that should make security teams nervous. Victims interacted with what appeared to be a legitimate custom AI assistant, only to be redirected through a chain that ended with a full-featured remote access trojan sitting on their machine.
How the attack works
The attackers built personalized GPT instances with innocuous-sounding names. One was called “Plus 5.6.” These custom GPTs were designed to steer conversations toward actions that ultimately sent victims to a Google Sites page masquerading as a Cloudflare CAPTCHA verification.
The fake CAPTCHA page prompted users to execute a PowerShell command. That single action kicked off an eight-stage ClickFix infection chain. The PowerShell command fetched a malicious MSI installer, which in turn deployed a remote access trojan with a concerning feature set: remote desktop control, audio and video capture, and the ability to drop additional payloads onto the compromised system.
Some variants of the attack used commands referencing a decimal IP address, 1614733393, which translates to 96.62.224.81. Using decimal notation instead of a standard dotted IP format is a known obfuscation technique, designed to slip past casual inspection and some URL filtering tools.
The distribution method was particularly clever. Victims often landed on the malicious Custom GPTs through sponsored Google search results for “chatgpt.” In other words, people searching for the real ChatGPT were served paid ads that led them to attacker-controlled GPT instances hosted on OpenAI’s own legitimate domain.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Scale and OpenAI’s response
Huntress linked the campaign’s Google Sites infrastructure to more than 40 incidents. At least two of those were traced directly back to the attacker-created Custom GPTs on chatgpt.com.
OpenAI moved to take down the first identified malicious GPT on September 25, 2026. Two days later, on September 27, a second malicious Custom GPT appeared. The speed of that replacement suggests the attackers had a repeatable playbook for spinning up new instances, treating takedowns as a minor inconvenience rather than a serious obstacle.
Why ClickFix keeps working
ClickFix attacks have been a growing problem throughout 2025 and 2026. The technique typically involves presenting users with what appears to be a system prompt or verification step, then asking them to copy and paste a command into their terminal or Run dialog. It works because it bypasses traditional malware delivery mechanisms. There’s no malicious attachment to scan, no executable to flag. The victim becomes the delivery mechanism by running the command themselves.
What makes this particular campaign notable is the trust amplifier. Previous ClickFix attacks have used fake error messages, fraudulent IT support pages, and compromised websites. Hosting the initial lure on chatgpt.com adds a layer of credibility that those approaches lacked.
The broader implications for AI platform security
For organizations, the takeaway is that domain-based trust policies need rethinking. Blanket-allowing traffic to chatgpt.com makes sense when the only content there is OpenAI’s own product. It makes considerably less sense when any user can create a GPT that redirects visitors to malicious infrastructure.
Security teams should consider monitoring for PowerShell execution patterns consistent with ClickFix chains, particularly commands that reference decimal-encoded IP addresses or fetch MSI installers from external sources.
The campaign also raises questions about the responsibility of search platforms. If attackers are purchasing sponsored search results to direct users toward malicious GPTs, ad verification processes clearly have gaps worth examining.