AI Chatbots Turned Weapons: ChatGPT Custom GPTs Hijacked for ClickFix Malware
Threat actors have found a new way to weaponize trusted AI platforms. In September 2026, cybersecurity researchers at Huntress uncovered a malicious campaign that abused OpenAI’s ChatGPT Custom GPTs to deliver malware through sophisticated ClickFix social engineering attacks. The discovery reveals how quickly adversaries adapt popular consumer AI tools into attack vectors, leaving everyday users dangerously exposed.
What Are Custom GPTs and Why Do They Matter
Custom GPTs are personalized versions of ChatGPT that anyone can build on ChatGPT.com. They allow creators to embed specific instructions, tools, and knowledge bases into a tailored chatbot experience. Because these GPTs are hosted on OpenAI’s own domain, they carry the implicit trust and legitimacy of the ChatGPT brand.
This trust is precisely what makes them attractive to attackers. A malicious Custom GPT looks and behaves like any other ChatGPT instance, complete with the familiar interface, the ChatGPT name at the top, and a builder profile that lends an air of authenticity. For most users, there is no obvious visual signal that something is wrong.
How the ClickFix Attack Chain Works
The ClickFix attack method has been circulating for some time, but pairing it with Custom GPTs represents a significant escalation. Here is how the campaign unfolded:
- Step 1 — Search Engine Poisoning: Victims searched Google for ChatGPT and were served a sponsored result linking to the malicious Custom GPT, titled “Plus 5.6” and attributed to a “community builder.”
- Step 2 — Fake Upgrade Prompt: When users interacted with the Custom GPT, it responded with a Google Sites link, claiming the primary domain had limited availability and directing users to a “backup domain.”
- Step 3 — Fake CAPTCHA Page: The backup domain hosted a fake Cloudflare CAPTCHA verification page, a hallmark of the ClickFix technique, instructing the victim to copy and execute a PowerShell command.
- Step 4 — Malware Execution: The PowerShell command downloaded and executed a malicious MSI installer, kicking off a multi-stage infection chain.
At least 40 users were confirmed infected through this campaign, with at least two incidents directly linked to the Custom GPT instance. OpenAI took down the first malicious GPT on September 25, but a second one was discovered just two days later on September 27, demonstrating the attacker’s persistence and adaptability.
Inside the Multi-Stage Infection Chain
DLL Sideloading and Persistence
The first Custom GPT served an installer that abused a legitimate Canon-signed application for DLL sideloading. This technique allows malicious code to execute under the guise of a trusted, digitally signed executable. Persistence was established through a Windows User Run key and a scheduled task disguised as “Canon Configuration Reader,” ensuring the malware survived reboots.
Audio File Concealment
The loader itself was concealed as an audio file, designed to bypass security protections and perform system reconnaissance checks before displaying a fake loading window to keep the victim unaware. The malicious code was then extracted from a heavily obfuscated audio file containing a custom archive with 315 folders and 806 files inside, including the final payload.
Remote Access Trojan Delivery
The final payload was a Remote Access Trojan (RAT) capable of fetching, processing, and executing various types of additional payloads. The malware fingerprinted the infected system and connected to its command-and-control server using DNS-over-HTTPS through Cloudflare, Google, and Quad9, making network traffic blend in with legitimate DNS queries.
Second Wave Adaptation
The second Custom GPT followed the same overall pattern but switched tactics. Instead of Canon executables, the attacker used a Stardock-signed application and a patched Stardock DLL. The loader was embedded within a Microsoft NuGet package rather than an audio file. This rapid adaptation shows how attackers iterate to avoid detection once a technique is exposed.
Why This Campaign Is a Wake-Up Call
The abuse of Custom GPTs for malware delivery highlights several critical security concerns that organizations and individuals must address:
- Platform Trust Exploitation: Attackers are increasingly leveraging the trust users place in well-known platforms. When malware originates from ChatGPT.com, users are far less likely to be suspicious than they would be of an unknown website.
- Sponsored Search as an Attack Vector: The fact that victims reached the malicious GPT through a sponsored Google search result underscores the danger of treating paid placements as inherently trustworthy.
- AI as a Social Engineering Tool: Unlike traditional phishing pages, an interactive chatbot can dynamically respond to user questions, build rapport, and tailor its manipulation in real time, making the social engineering far more convincing.
- Speed of Iteration: The rapid appearance of a second malicious GPT after the first was taken down demonstrates that attackers can spin up new instances faster than platforms can respond.
Best Practices for Defending Against AI-Powered Social Engineering
As AI platforms become attack surfaces, defenders must update their security strategies accordingly:
- Verify sponsored results carefully: Sponsored search links are not vetted for trustworthiness. Always cross-reference the destination URL against the official source before clicking.
- Be wary of “community” or “third-party” GPTs: Custom GPTs built by unknown authors should be treated with caution, especially if they prompt users to visit external websites or execute commands.
- Never execute PowerShell commands from web pages: No legitimate CAPTCHA or verification process will ever ask you to run PowerShell, Command Prompt, or any terminal command. This is an immediate red flag.
- Deploy endpoint detection and response (EDR): Modern EDR solutions can detect DLL sideloading, suspicious scheduled tasks, and anomalous DNS-over-HTTPS traffic, all of which were present in this campaign.
- Monitor DNS-over-HTTPS traffic: Attackers increasingly abuse DoH to hide C2 communications. Organizations should consider DNS filtering and monitoring solutions that can inspect DoH traffic for indicators of compromise.
- Implement application allowlisting: Restrict which executables can run on endpoints. This limits the effectiveness of DLL sideloading attacks that abuse legitimate signed binaries.
The Broader Trend: AI Tools as Attack Infrastructure
The ChatGPT Custom GPT campaign is part of a broader pattern. Throughout 2026, threat actors have repeatedly demonstrated that they can repurpose consumer AI platforms for offensive operations. From AI-generated phishing content to automated reconnaissance and now interactive social engineering chatbots, the line between legitimate AI tools and attack infrastructure continues to blur.
Security teams must recognize that AI platforms are no longer just productivity tools to protect, they are also potential weapons that can be turned against their users. This dual-use nature demands a new approach to threat modeling that accounts for the weaponization of trusted consumer platforms.
What Organizations Should Do Now
For IT and security leaders, the immediate takeaways are clear:
- Update security awareness training to include AI platform abuse scenarios, specifically the dangers of Custom GPTs and ClickFix-style attacks.
- Block execution of PowerShell from browser contexts using application control policies or Windows Defender Application Control.
- Monitor for DLL sideloading patterns involving legitimate signed executables from vendors like Canon or Stardock.
- Report malicious Custom GPTs to OpenAI immediately if discovered within your organization or user base.
- Educate users that no AI chatbot, regardless of how legitimate it appears, should ever instruct them to run system commands or download software from third-party links.
As threat actors continue to innovate, the security community must move just as quickly. The weaponization of ChatGPT Custom GPTs is not a one-off incident, it is a preview of how attackers will increasingly use trusted AI infrastructure to reach their victims. Staying ahead requires vigilance, education, and a willingness to question the legitimacy of even the most familiar platforms.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.
