Fake ChatGPT “Plus 5.6” GPT Pushes ClickFix RAT

The Hacker News · High sophistication
Last updated September 30, 2026

Researchers observed threat actors creating attacker-made ChatGPT Custom GPTs that look legitimate, then steering users to a Google Sites “backup domain.” Victims are shown a fake Cloudflare CAPTCHA that tricks them into copying and running a malicious PowerShell command, which downloads and runs malware via an MSI installer. Huntress reports at least 40 infections tied to this campaign.

Key findings

  • Attackers created malicious ChatGPT Custom GPTs and used them as a trusted entry point to redirect users to a Google Sites link.
  • The malicious Custom GPT displayed a “Service Availability Notice” urging users to upgrade or use a backup domain due to “limited availability on the primary domain.”
  • The backup site showed a fake Cloudflare CAPTCHA that triggered a ClickFix flow and tricked users into copying/executing a malicious PowerShell command.
  • The PowerShell command deployed an MSI installer (“ISOSimple.msi”) leading to a multi-stage infection chain and a RAT; Huntress reported “No less than 40 users have been infected.”
  • Initial access was driven by sponsored Google search results for terms like “chatgpt.”

Who’s being targeted

  • Commonly targeted roles: All Employees, Executives, IT Helpdesk, Security Awareness, Users who frequently use AI tools / web searches.
  • Affected industries: Multiple / cross-industry (any organization using ChatGPT or web search ads).
  • Attack channels: website.
  • Impersonated: ChatGPT / a legitimate ChatGPT Custom GPT (“Plus 5.6”), Cloudflare (fake CAPTCHA/interstitial).

Awareness takeaways

  • Treat “backup domain” links from trusted platforms as suspicious, verify the destination before clicking.
  • Never copy/paste and run commands (PowerShell/Terminal) just to pass a CAPTCHA or ‘verification’ step.
  • Be cautious with sponsored search results for high-interest services (e.g., “chatgpt”), ads can be the starting point for scams.
  • Assume attackers will abuse well-known brands and trusted platforms (AI tools, Google Sites) to make lures look legitimate.

Red flags to watch for

  • A ChatGPT GPT unexpectedly directs you off-platform to a third-party “backup domain.”
  • High-pressure language implying you must act now to get “immediate access.”
  • Unusual instruction to change subscription tier or use an external site to continue.
  • CAPTCHA/verification pages should never require copying and running PowerShell/commands.
  • Unexpected software download/install prompted by a web page verification step.
  • Being routed through an untrusted “backup” site before a CAPTCHA appears.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You search Google for “chatgpt,” click a sponsored result, and land on a Custom GPT called “Plus 5.6.” Looks legit, right? Instead of answering you, Plus 5.6 pops up a big “Service Availability Notice,” telling you to click a Google Sites backup domain for immediate access. That’s the setup. Click it, and you hit a fake Cloudflare CAPTCHA that tells you to copy and run a PowerShell command. That one command quietly pulls down an MSI called ISOSimple.msi and installs a remote access trojan. Your move: if any GPT or “verification” page tells you to copy and run PowerShell or terminal commands, stop right there and close the tab.

Similar attacks

Fake ChatGPT GPTs Trick Users Into Running PowerShell

Fake ChatGPT GPTs Trick Users Into Running PowerShell

Attackers abused real ChatGPT “Custom GPT” pages and a fake Cloudflare CAPTCHA to trick users into copying and pasting a PowerShell command on Windows. That command installed a malicious MSI and led to a multi-stage infection ending in a remote access trojan (RAT) with deep control of the victim’s…

September 30, 2026
Fake ChatGPT “Custom GPT” Pushes ClickFix Malware

Fake ChatGPT “Custom GPT” Pushes ClickFix Malware

A real ClickFix campaign abused ChatGPT “Custom GPTs” to impersonate legitimate tools and trick people into running PowerShell commands on their own computers. Victims were funneled from a sponsored Google result to a fake “backup domain” on Google Sites with a Cloudflare CAPTCHA-style prompt,…

September 29, 2026
Fake “ChatGPT” GPT Uses ClickFix to Drop RAT

Fake “ChatGPT” GPT Uses ClickFix to Drop RAT

Researchers found a real malware campaign where attackers abused ChatGPT “CustomGPTs” and Google sponsored search results to funnel victims to a fake ChatGPT experience. Victims are shown a fake “Service Availability Notice” and pushed to a “backup domain” that looks like a Cloudflare CAPTCHA,…

September 30, 2026
Fake Custom GPT Pushes ‘CAPTCHA’ RAT Install

Fake Custom GPT Pushes ‘CAPTCHA’ RAT Install

Attackers used sponsored Google search ads to lure people to a malicious ChatGPT Custom GPT (“Plus 5.6”) hosted on the real chatgpt.com site. The Custom GPT redirected victims to a fake Cloudflare CAPTCHA page that instructed them to copy/paste a command into a terminal, leading to installation of…

September 29, 2026
Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026
Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Attackers compromised Brevo’s Cloudflare setup using a long-lived API key found in source code, then altered website content at the CDN edge. Visitors were shown fake Cloudflare verification prompts to run Windows commands, and logged-in WordPress admins were targeted with a hidden backdoor plugin…

September 22, 2026