A New Wave of ClickFix Attacks Leverages ChatGPT Custom GPTs to Dupe Victims into Executing Malicious Code
Cybersecurity firm Huntress has uncovered a disturbing trend in which hackers are using personalized versions of the popular chatbot platform, ChatGPT, to launch sophisticated phishing attacks on unsuspecting victims. Dubbed “ClickFix,” this campaign involves creating custom ChatGPT instances that impersonate legitimate products and trick users into executing malicious PowerShell commands on their machines.
At least 40 users have fallen victim to these tactics, with two incidents connected to a single Custom GPT instance. The attackers’ success can be attributed to the fact that they are exploiting the very features that make chatbots like ChatGPT so appealing: their ability to understand and respond to user prompts in a natural way.
The ClickFix campaign relies on users searching for “ChatGPT” on Google, where they are served a sponsored result featuring a custom ChatGPT instance. The attackers have cleverly crafted these instances to appear legitimate, with titles like “Plus 5.6” and descriptions that claim the chatbot is from a reputable “community builder.” Once the user engages with the Custom GPT, they are presented with a fake notice claiming limited availability of the service and requesting an upgrade or use of the primary domain.
However, if the victim attempts to access the primary domain, they are redirected to a Google Sites page hosting a Cloudflare CAPTCHA check. This is where things get really sinister: the attackers have designed this page to instruct the user to execute a PowerShell command that downloads and executes a malicious installer. The first Custom GPT served an installer that abused a legitimate Canon-signed application for DLL sideloading, while the second instance used a Stardock executable and a patched Stardock DLL.
The infection chain is complex and multi-staged, involving a loader concealed as an audio file designed to bypass security protections. This loader performs system checks, displays a fake loading window, and eventually loads malicious code from a heavily obfuscated audio file containing a custom archive with hundreds of files inside. The final payload is a Remote Access Trojan (RAT) capable of fetching, processing, and executing various types of payloads.
The fact that these attacks are leveraging ChatGPT Custom GPTs makes them particularly concerning, as they can be hosted on legitimate platforms like Google Sites and Cloudflare. This raises questions about the responsibility of companies like OpenAI to detect and prevent such abuse of their services.
As we continue to rely more heavily on AI-powered tools in our daily lives, it’s essential that we remain vigilant against these types of threats. To protect yourself from ClickFix-style attacks, be cautious when interacting with chatbots or sponsored results online, and never execute PowerShell commands or download software from untrusted sources. By staying informed and taking proactive measures to secure your digital life, you can minimize the risk of falling victim to these sophisticated phishing tactics.
Source: SecurityWeek — 2026-09-29