Threat actors are abusing ChatGPT Custom GPTs to make malicious websites appear legitimate and trick users into downloading malware, according to cybersecurity company Huntress.
The campaign, observed in late September 2026, uses attacker-created Custom GPTs hosted on the legitimate ChatGPT website. The fake GPTs are designed to appear like genuine product offerings before directing users to external websites that use ClickFix-style social engineering attacks.
Huntress said victims who interacted with one of the malicious Custom GPTs were shown a message containing a Google Sites link. The link redirected them to a fake service page that eventually presented a fraudulent Cloudflare CAPTCHA. The fake verification process was designed to convince users to copy and execute a malicious command on their computers.
The campaign reportedly resulted in at least 40 infections.
The attack begins with sponsored Google search results for queries such as “chatgpt.” Users who click on the malicious Custom GPT are presented with a service availability message claiming that access to the primary domain is limited. They are then encouraged to use a backup Google Sites domain instead.
The fake Google Sites page uses a ClickFix-style CAPTCHA to persuade victims to execute a command. The resulting infection chain deploys an MSI installer and eventually loads a remote-access trojan.
According to Huntress, the malware uses a technique known as DLL sideloading to load malicious code through a legitimate signed application. The malware also hides part of its payload inside a WAV audio file, which is then used as part of the loading process.
The final malware is designed to collect extensive information from infected computers. Huntress said it can identify installed security software, check Microsoft Defender status and gather information about the affected system.
The RAT can also provide remote desktop and screen access, capture camera and microphone input, record system audio, search files, and download additional executables and scripts.
The malware reportedly recognizes multiple web browsers and can launch a default browser. It can also search files across an infected system and execute additional EXE, DLL and MSI files as well as PowerShell, batch, VBScript and JavaScript scripts.
The malware uses DNS-over-HTTPS to communicate with its command-and-control infrastructure. Huntress said the technique uses major public DNS providers, including Cloudflare, Google and Quad9, allowing the traffic to blend into normal HTTPS communications and making it less visible in traditional DNS logs.
The researchers also observed the malware dropping a legitimately signed application that launches Google Chrome using a temporary browser profile.
Huntress said the campaign demonstrates how attackers are increasingly abusing trusted online platforms to make social engineering attacks appear credible. Rather than simply creating fake websites from scratch, attackers can use legitimate services such as ChatGPT and Google Sites as parts of their delivery infrastructure.
The activity is part of a wider increase in ClickFix campaigns. Security researchers have recently observed similar attacks using fake AI product websites, compromised websites, malicious advertisements, phishing emails and fraudulent CAPTCHA pages.
Some campaigns have used fake versions of AI services such as OpenAI Codex and Anthropic Claude to convince users to install malicious software. Other attacks have relied on compromised websites and fake CAPTCHA pages to distribute information stealers, remote-access tools and other malware.
Researchers have also observed ClickFix campaigns using blockchain-based techniques to hide command-and-control infrastructure and campaigns targeting government systems.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The growing use of trusted platforms in these attacks highlights the risks of treating familiar websites, AI assistants and CAPTCHA verification pages as automatically safe. Users should be especially cautious when a website or AI service unexpectedly asks them to copy commands into PowerShell, Terminal or another system tool.



