AI Weekly Malaysia

Back to items Summaries

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

ID
30407
Status
summarized
Published
30 Sep 2026, 11:00 PM
Fetched
01 Oct 2026, 1:13 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
01 Oct 2026, 1:14 AM
Tags
Audience
developersvibe_codersai_agent_usersfounders

What happened

Huntress observed a late-September 2026 campaign where attackers published two Custom GPTs on chatgpt.com (both named "Plus 5.6") and promoted them through Google sponsored results for searches like "chatgpt." When a victim prompts the GPT, it replies with a Google Sites link that shows a fake Cloudflare CAPTCHA, triggering a ClickFix attack that tells the user to copy and run a PowerShell command, which drops an MSI installer ("ISOSimple.msi") that chains DLL sideloading, shellcode, a persistence script, and a RAT payload. Huntress says no fewer than 40 users were infected, and notes earlier campaigns abused shared ChatGPT conversations and malicious Claude Artifacts the same way.

Why it matters

The delivery channel is a legitimate chatgpt.com URL plus a sponsored ad, so URL-reputation checks and 'is this really OpenAI's domain' instincts both fail. If you or your users install Custom GPTs found via search ads, treat any reply that hands you a backup-domain link or a PowerShell command to paste as the payload, not support — and note the same pattern has already been run through shared ChatGPT conversations and Claude Artifacts, so it isn't specific to one vendor's feature.

Discussion angle

ClickFix has moved from fake CAPTCHAs on random sites to a reply inside a Custom GPT on OpenAI's own domain — is 'never paste a command an AI or a webpage hands you' now a policy you enforce on machines, or still just advice you hope people follow?

Top