Decoding the world of cybersecurity

Malicious GPTs feed ClickFix malware chain

Huntress says attackers are using custom ChatGPT instances to send victims into a ClickFix social-engineering chain that ultimately deploys remote-access malware.

Malicious GPTs feed ClickFix malware chain
Summary
  • Attackers configured malicious Custom GPTs to direct users towards Google Sites pages carrying a ClickFix lure.
  • Huntress investigated at least 40 incidents tied to the campaign infrastructure and directly confirmed two Custom GPT-driven infections.
  • One reported GPT was removed, but Huntress subsequently identified another linked to the same campaign.

Attackers are using maliciously configured Custom GPTs as an entry point to a ClickFix malware campaign, according to Huntress research showing how trusted generative-AI interfaces are being incorporated into conventional social engineering.

Huntress says victims interacted with attacker-created Custom GPTs hosted on the legitimate ChatGPT service. The instances were configured to return links to Google Sites pages controlled by the campaign.

Those pages presented a ClickFix-style lure that instructed users to copy and run a command. The command retrieved a PowerShell script and began a multi-stage infection chain that ultimately deployed remote-access malware.

Huntress says the chain used legitimate signed software as part of DLL side-loading, including a Canon-signed executable in analysed incidents. The malicious components were then able to establish persistent attacker access.

The company’s security operations centre investigated at least 40 incidents associated with the Google Sites infrastructure used by the campaign. It directly confirmed that two infections began through Custom GPT interactions.

That evidential boundary is important. The findings do not establish that all 40 incidents originated through ChatGPT or that Custom GPTs represented the dominant distribution mechanism. They show that the same campaign infrastructure supported at least two confirmed GPT-driven infections.

Huntress reported one identified malicious GPT to OpenAI, and it had been removed by 25 September. Researchers found another Custom GPT linked to the campaign on 27 September.

The technique adds a new distribution layer to an established attack pattern rather than introducing a new malware capability. ClickFix attacks work by convincing users to perform actions themselves, often bypassing controls designed to stop hostile attachments or automatic code execution.

Generative-AI interfaces can strengthen that social engineering because users expect them to provide procedural guidance and external references. An attacker does not need to compromise the underlying AI platform if a custom instance can simply be configured to provide malicious instructions and links.

The pattern resembles longstanding abuse of other legitimate services. Attackers routinely use cloud storage, document-sharing systems, advertising platforms, code repositories, and compromised websites because trusted infrastructure reduces suspicion and can evade crude filtering.

Conversational AI adds another surface whose content is dynamic and responsive rather than static.

That creates an enterprise trust problem. Content received through a public AI service cannot be treated as safe simply because the service hosting the conversation is legitimate. The harmful component may sit in the custom instructions, linked content, or downstream actions rather than in a vulnerability in the AI platform.

The rapid appearance of a second GPT after the first was removed also shows the limitations of one-off takedowns. Attack infrastructure can be rebuilt cheaply where the campaign relies on legitimate services and social engineering rather than a hard-to-reproduce exploit.

Huntress’ findings are therefore evidence of familiar tradecraft adapting to a new interface. The campaign does not demonstrate compromise of ChatGPT itself; it demonstrates that attacker-controlled conversational experiences can now function as part of the lure.

×