Skip to main content
Emerging ThreatsMalware & Ransomware

ChatGPT Abused to Deliver Trojan Malware via ClickFix Attacks

Person sitting at desk, concerned, examining laptop with blurred screen, surrounded by papers and notes.
"Every step of the attack also borrows a brand people already trust, from ChatGPT and Google to Cloudflare and even Canon software," Huntress said. "No legitimate website will ever ask you to copy and paste a command to prove you’re human."

Huntress discovery and timeline

Security researchers at Huntress uncovered a malware campaign active since September that combines abuse of ChatGPT's CustomGPT feature with a social-engineering technique known as ClickFix. The firm reported at least 40 infections tied to the campaign and told reporters it notified Open AI; the malicious CustomGPT named Plus 5.6 was taken down as of September 25. Huntress has since identified a new CustomGPT they link to the same activity and warned ChatGPT users to exercise caution.

Plus 5.6 CustomGPT and sponsored-search routing

The attackers built a CustomGPT called Plus 5.6 designed to look like a legitimate ChatGPT offering. Huntress found that victims were lured to Plus 5.6 through sponsored search results after searching for 'chatgpt' on Google. Once on the attacker-controlled page, users were shown a "Service Availability Notice" claiming limited availability on the "primary domain" and steering them to a "backup domain."

ClickFix attack disguised as a Cloudflare CAPTCHA

The campaign's backup domain initially resembles a Cloudflare CAPTCHA check. That page asks the user to paste a command to "verify" themselves — the precise prompt that enables the ClickFix attack. ClickFix leverages social engineering to get victims to paste and execute attacker-supplied commands on their own machines; because the victim runs the commands, the technique often bypasses endpoint protections, Huntress explained.

MSI installer, Canon-signed sideloading, and a RAT

Following the ClickFix step, the user is directed to a malicious Microsoft Software Installer (MSI). Huntress's analysis shows the MSI deploys a legitimate Canon-signed application that the attackers have used to sideload malicious code. That chain establishes persistence on the infected machine and ultimately delivers a remote access trojan (RAT).

According to Huntress, the delivered RAT can monitor the system, capture audio and video from microphones and cameras, exfiltrate data to a command-and-control server operated by the attackers, and deliver additional malware or payloads to the compromised device.

What this means for ChatGPT users, security teams, and enterprises

  • ChatGPT users: Individuals searching for ChatGPT or related tools can be targeted by sponsored search results that mimic official offerings. Huntress's advisory implies users should be wary of prompts that ask them to paste and execute commands locally.
  • Security teams and technologists: The campaign demonstrates a blended abuse of platform features (CustomGPT) and classic social engineering (ClickFix), plus software sideloading via a signed MSI. Teams should monitor for unusual MSI installations and sideload behavior consistent with the chain described by Huntress.
  • Enterprises and procurement leaders: The attackers borrowed established vendor brands — from ChatGPT and Google to Cloudflare and Canon — to build trust and social-proof. Procurement and security review processes that assume legitimacy based on branding alone may be insufficient against this pattern.

Conclusion

Huntress's analysis exposes a multi-stage campaign that fuses platform feature abuse with a well-known social-engineering trick and a sideloading method that uses a legitimate, signed application to conceal malicious code. With at least 40 infections identified and a replacement CustomGPT already noted by researchers after the takedown of Plus 5.6, the attack illustrates how quickly adversaries can recombine trusted brands and platform features into new delivery chains. For now, the firm’s blunt guidance is simple and specific: never paste and run a command to "prove" you are human — and treat unexpected prompts that channel you off a known vendor domain as a serious red flag.

https://www.infosecurity-magazine.com/news/chatgpt-feature-abuse-to-deliver/