{"slug": "hackers-exploit-chatgpt-custom-gpts-to-launch-clickfix-social-engineering", "title": "Hackers exploit ChatGPT custom GPTs to launch ClickFix social engineering attacks", "summary": "Huntress researchers uncovered a late-September 2026 campaign in which attackers created malicious Custom GPTs on chatgpt.com that funneled victims into an eight-stage ClickFix infection chain ending in a remote access trojan with remote desktop control, audio and video capture, and secondary payload delivery. Huntress linked the campaign's Google Sites infrastructure to more than 40 incidents, at least two of which traced back to the attacker-created Custom GPTs, and OpenAI took down the first identified malicious GPT on September 25, 2026, before a second appeared on September 27. Victims reached the fake assistants, including one named \"Plus 5.6,\" largely through sponsored Google search results for \"chatgpt,\" and some variants used the decimal IP address 1614733393 (96.62.224.81) to evade inspection.", "body_md": "FoxTPNL / Wikimedia Commons (CC BY 4.0)\n\n# Hackers exploit ChatGPT custom GPTs to launch ClickFix social engineering attacks\n\nAttackers built fake custom GPTs on OpenAI's platform to funnel victims into an eight-stage malware infection chain, researchers found\n\nSomeone finally figured out how to weaponize the custom GPT feature that [OpenAI](https://cryptobriefing.com/markets/openai/) launched to much fanfare. Researchers at Huntress uncovered a campaign in late September 2026 where attackers created malicious Custom GPTs on chatgpt.com, using the trusted OpenAI domain as the opening move in a multi-stage malware attack.\n\nThe scheme is elegant in a way that should make security teams nervous. Victims interacted with what appeared to be a legitimate custom AI assistant, only to be redirected through a chain that ended with a full-featured remote access trojan sitting on their machine.\n\n## How the attack works\n\nThe attackers built personalized GPT instances with innocuous-sounding names. One was called “Plus 5.6.” These custom GPTs were designed to steer conversations toward actions that ultimately sent victims to a [Google](https://cryptobriefing.com/markets/alphabet/) Sites page masquerading as a Cloudflare CAPTCHA verification.\n\nThe fake CAPTCHA page prompted users to execute a PowerShell command. That single action kicked off an eight-stage ClickFix infection chain. The PowerShell command fetched a malicious MSI installer, which in turn deployed a remote access trojan with a concerning feature set: remote desktop control, audio and video capture, and the ability to drop additional payloads onto the compromised system.\n\nSome variants of the attack used commands referencing a decimal IP address, 1614733393, which translates to 96.62.224.81. Using decimal notation instead of a standard dotted IP format is a known obfuscation technique, designed to slip past casual inspection and some URL filtering tools.\n\nThe distribution method was particularly clever. Victims often landed on the malicious Custom GPTs through sponsored Google search results for “chatgpt.” In other words, people searching for the real ChatGPT were served paid ads that led them to attacker-controlled GPT instances hosted on OpenAI’s own legitimate domain.\n\n### AI, tech, and the markets they move—in one daily briefing.\n\nDaily. Free. Join 34,000+ readers across crypto, finance, and policy.\n\n## Scale and OpenAI’s response\n\nHuntress linked the campaign’s Google Sites infrastructure to more than 40 incidents. At least two of those were traced directly back to the attacker-created Custom GPTs on chatgpt.com.\n\nOpenAI moved to take down the first identified malicious GPT on September 25, 2026. Two days later, on September 27, a second malicious Custom GPT appeared. The speed of that replacement suggests the attackers had a repeatable playbook for spinning up new instances, treating takedowns as a minor inconvenience rather than a serious obstacle.\n\n## Why ClickFix keeps working\n\nClickFix attacks have been a growing problem throughout 2025 and 2026. The technique typically involves presenting users with what appears to be a system prompt or verification step, then asking them to copy and paste a command into their terminal or Run dialog. It works because it bypasses traditional malware delivery mechanisms. There’s no malicious attachment to scan, no executable to flag. The victim becomes the delivery mechanism by running the command themselves.\n\nWhat makes this particular campaign notable is the trust amplifier. Previous ClickFix attacks have used fake error messages, fraudulent IT support pages, and compromised websites. Hosting the initial lure on chatgpt.com adds a layer of credibility that those approaches lacked.\n\n## The broader implications for AI platform security\n\nFor organizations, the takeaway is that domain-based trust policies need rethinking. Blanket-allowing traffic to chatgpt.com makes sense when the only content there is OpenAI’s own product. It makes considerably less sense when any user can create a GPT that redirects visitors to malicious infrastructure.\n\nSecurity teams should consider monitoring for PowerShell execution patterns consistent with ClickFix chains, particularly commands that reference decimal-encoded IP addresses or fetch MSI installers from external sources.\n\nThe campaign also raises questions about the responsibility of search platforms. If attackers are purchasing sponsored search results to direct users toward malicious GPTs, ad verification processes clearly have gaps worth examining.\n\n**Disclosure:** This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our\n\n[Editorial Policy](https://cryptobriefing.com/editorial-policy/).", "url": "https://wpnews.pro/news/hackers-exploit-chatgpt-custom-gpts-to-launch-clickfix-social-engineering", "canonical_source": "https://cryptobriefing.com/hackers-exploit-chatgpt-custom-gpts-clickfix-attacks/", "published_at": "2026-09-29 13:10:09+00:00", "updated_at": "2026-09-29 13:19:57.626725+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "generative-ai", "ai-products"], "entities": ["OpenAI", "ChatGPT", "Huntress", "Google", "Google Sites", "Cloudflare", "Plus 5.6", "Microsoft"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/hackers-exploit-chatgpt-custom-gpts-to-launch-clickfix-social-engineering", "markdown": "https://wpnews.pro/news/hackers-exploit-chatgpt-custom-gpts-to-launch-clickfix-social-engineering.md", "text": "https://wpnews.pro/news/hackers-exploit-chatgpt-custom-gpts-to-launch-clickfix-social-engineering.txt", "jsonld": "https://wpnews.pro/news/hackers-exploit-chatgpt-custom-gpts-to-launch-clickfix-social-engineering.jsonld"}}