Fake ChatGPT 'Custom GPTs' Used to Trick Users into Installing Remote Access Malware
Security researchers at Huntress have uncovered a campaign abusing ChatGPT's Custom GPT feature to spread malware. Attackers created fake Custom GPTs, appearing under names like "Plus 5.6", that show up in sponsored Google search results for terms like "chatgpt". When users interact with these fake GPTs, they are told there is a "Service Availability Notice" and pushed towards a "backup" link hosted on Google Sites.
That backup site presents a fake Cloudflare CAPTCHA check, a technique known as ClickFix, which tricks victims into copying and running a malicious PowerShell command themselves. This leads to the download of a disguised installer that abuses a legitimate, signed Canon application file to load a hidden malicious file, ultimately installing a remote access trojan (RAT) that gives attackers control over the infected device. At least 40 users have been infected so far.
This campaign follows a pattern of attackers abusing trust in well known AI platforms, with previous incidents involving shared AI chatbot conversations and malicious Claude Artifacts also used to spread stealer malware and RATs. Because these attacks rely on the user copying and running a command themselves, technical filters alone may not stop them.