Fake ChatGPT “Custom GPT” Pushes ClickFix Malware

Security Week Feed · High sophistication
Last updated September 30, 2026

A real ClickFix campaign abused ChatGPT “Custom GPTs” to impersonate legitimate tools and trick people into running PowerShell commands on their own computers. Victims were funneled from a sponsored Google result to a fake “backup domain” on Google Sites with a Cloudflare CAPTCHA-style prompt, which instructed them to run commands that downloaded a malicious installer and ultimately deployed a remote access trojan (RAT).

How the attack worked

This campaign combined malvertising, impersonation, and ClickFix-style execution tricks. Attackers created malicious ChatGPT Custom GPTs and used Google sponsored search results to place them at the top of search rankings for people looking for ChatGPT. Victims who clicked through were directed to a Google Sites page presented as a legitimate backup domain, complete with a Cloudflare CAPTCHA-style check. That page instructed users to run PowerShell commands, which downloaded a malicious MSI installer as part of a multi-stage infection chain, ultimately deploying a remote access trojan.

Why it succeeded

The attack relied on trust in familiar-looking infrastructure rather than technical exploits. A sponsored Google result gave the fake tool an appearance of legitimacy, and the notice claiming limited availability on the primary domain gave victims a plausible reason to follow a link to an unfamiliar site. Once there, a CAPTCHA-style verification step made running a command feel like a routine security check rather than a red flag. According to the reporting, at least 40 users were infected, and at least two incidents were linked directly to a Custom GPT instance. The campaign also used signed or legitimate software components, including a Canon-signed application and later a Stardock executable and DLL, to aid execution and evasion.

What to watch for

  • Sponsored search results leading to an unexpected "Custom GPT" or AI tool page
  • Messages claiming "limited availability" that push users toward a "backup domain"
  • A Google Sites page or similar hosting a CAPTCHA-style prompt
  • Any instruction to open PowerShell or a terminal to "verify" or "fix" access to a service

OpenAI removed one malicious GPT identified in this campaign, but a second appeared shortly after, showing that takedowns alone do not stop the technique.

How to build resistance

  • Treat sponsored search results as untrusted and verify you are on an official site before logging in or following instructions
  • Train staff, including IT helpdesk, developers, and executives, to never run PowerShell or terminal commands from a website or CAPTCHA page
  • Escalate any "backup domain" or "limited availability" prompt to security teams before acting on it
  • Encourage use of approved, verified AI tools and reporting of suspicious third-party GPTs or plugins

Huntress noted that threat actors are finding success in this specific abuse of Custom GPTs for social engineering and are continuing to rely on this technique, which suggests organizations should expect similar lures involving other popular AI tools going forward.

Key findings

  • Threat actor created malicious ChatGPT Custom GPTs that returned a Google Sites link to a ClickFix page.
  • Victims were driven to the malicious Custom GPT via Google sponsored search results.
  • The ClickFix page instructed users to run PowerShell commands that downloaded a malicious MSI installer (multi-stage chain).
  • At least 40 users were infected; Huntress linked at least two incidents directly to a Custom GPT instance.
  • OpenAI removed one malicious GPT, but a second appeared shortly after.
  • Campaign used signed/legitimate software components (e.g., Canon-signed app; later switched to Stardock executable/DLL) to aid execution and evasion.

Who’s being targeted

  • Commonly targeted roles: All staff, IT helpdesk, Developers/engineers, Security team, Executives (high-level awareness of ad/impersonation risk).
  • Affected industries: Any organization whose employees use ChatGPT/AI tools, Information technology, Professional services, Finance (where users can be targeted via ads/search).
  • Attack channels: website.
  • Impersonated: A legitimate ChatGPT/AI tool and its “community builder”.

Red flags to watch for

  • Sponsored search result leading to an unexpected ‘Custom GPT’ page
  • Being asked to use a ‘backup domain’ hosted on Google Sites
  • Any site instructing you to run PowerShell commands to ‘fix’ or ‘verify’ access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a ClickFix attack?

ClickFix is a social engineering technique where a fake webpage, often disguised as a CAPTCHA or verification check, instructs the victim to manually run a PowerShell command that downloads and installs malware.

How were victims lured into this attack?

Victims searched for ChatGPT on Google, clicked a sponsored search result, and were directed to a malicious Custom GPT that pointed them to a fake backup domain hosted on Google Sites.

Why did the fake backup domain trick work?

The page displayed a notice claiming limited availability on the primary domain and asked users to use a backup domain, a common tactic to move victims onto attacker-controlled infrastructure.

What should employees do if a website asks them to run PowerShell commands?

They should never run PowerShell or terminal commands from a website or CAPTCHA-style prompt, and should instead escalate the request to IT or security teams for verification.

Read the video transcript

You Google “ChatGPT”, click the top sponsored result, and land on a Custom GPT that looks totally legit. It pops up a notice: “Limited availability through the primary domain. Please upgrade or use the service through our backup domain,” and hands you a Google Sites link. The backup site shows a fake Cloudflare-style check and tells you to run a PowerShell command to ‘verify access’, that command quietly pulls down a malicious installer and a remote access trojan. Here’s the move: if any website or Custom GPT ever tells you to run PowerShell or terminal commands, stop immediately and send a screenshot to IT or Security.

Similar attacks

Fake Custom GPT Pushes ‘CAPTCHA’ RAT Install

Fake Custom GPT Pushes ‘CAPTCHA’ RAT Install

Attackers used sponsored Google search ads to lure people to a malicious ChatGPT Custom GPT (“Plus 5.6”) hosted on the real chatgpt.com site. The Custom GPT redirected victims to a fake Cloudflare CAPTCHA page that instructed them to copy/paste a command into a terminal, leading to installation of…

September 29, 2026
Google Doc “Fix” Trick Delivers Malware

Google Doc “Fix” Trick Delivers Malware

A real-world social engineering attempt used a legitimate Google Doc to trick a target into manually running commands that installed malware. The attacker posed as a crypto marketing executive and used a fake “decryption failure” message and a “manual update” button as the lure, leading to an…

September 21, 2026
Fake Cloudflare CAPTCHA Tricks Users Into Running Code

Fake Cloudflare CAPTCHA Tricks Users Into Running Code

A campaign dubbed “TerminalFix” uses compromised websites to display fake Cloudflare CAPTCHA checks that instruct visitors to copy and run a PowerShell command. The goal is to get a user to run attacker-provided commands themselves, which can lead to persistent access and deeper intrusion into the…

August 31, 2026
Fake reCAPTCHA “Fix” Spreads MaaS Malware

Fake reCAPTCHA “Fix” Spreads MaaS Malware

Researchers observed real campaigns using compromised WordPress sites to show fake verification/BSOD-style prompts that trick users into running a copied PowerShell command. The technique (ClickFix) was paired with MaaS tools (ErrTraffic and Cruciferra) to deliver malware while attempting to kill…

August 19, 2026
Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Attackers compromised Brevo’s Cloudflare setup using a long-lived API key found in source code, then altered website content at the CDN edge. Visitors were shown fake Cloudflare verification prompts to run Windows commands, and logged-in WordPress admins were targeted with a hidden backdoor plugin…

September 22, 2026
Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026