www.infosecurity-magazine.com 30 Sept 2026, 11:30 UTC

Fake ChatGPT CustomGPT Campaign Uses ClickFix to Deploy RATs

CyberSIXT Evidence Panel Source marked as original reporting

CYBERCRIMINALS have fused a legitimate ChatGPT feature with the ClickFix technique to deliver malware, according to Huntress. The campaign leverages CustomGPTs—personalised ChatGPT instances that follow specific instructions—to impersonate real products and direct victims to malicious sites.

In one instance, attackers created a CustomGPT named Plus 5.6 that appears like the real ChatGPT and is surfaced through sponsored Google search results for “chatgpt.” When a user visits the page, Plus 5.6 presents a “Service Availability Notice” that claims limited access on the main domain and redirects to a “backup domain.”

The backup domain initially resembles a CloudFlare CAPTCHA check, prompting the user to paste a command to verify themselves. This is the classic ClickFix social-engineering step, which leads the user to download and run attacker-supplied commands, effectively bypassing standard protections once executed on the victim’s machine. The link then points to a malicious MSI that installs a Canon-signed application used to sideload malicious code and establish persistence, delivering a remote access Trojan (RAT).

The RAT can monitor the system, capture audio and video from microphones and cameras, and exfiltrate data to a command-and-control server, while also allowing delivery of additional malware.

Huntress reports at least 40 infections tied to the campaign, and notes that the Plus 5.6 CustomGPT was turned over to OpenAI and taken down by 25 September. Researchers have already identified a new CustomGPT linked to the same operation, with Huntress warning ChatGPT users to exercise caution.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline