Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks.
By Dillip Chowdary β’ Oct 01, 2026 β’ Source: BleepingComputer
Custom ChatGPTs push ClickFix attacks: what actually changed
Custom ChatGPTs push ClickFix attacks to deploy RAT malware By Bill Toulas September 29, 2026 04:59 PM 0 Custom variants of OpenAIβs ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. The threat actor is abusing the legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task that combines instructions, extra knowledge, and skills.
OpenAI hosts these custom GPTs, which can be published for others to install and use. The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.
Custom ChatGPTs push ClickFix attacks: how it works

The threat actor named the malicious GPT model 'Plus 5.6' and configured it to direct users to an alleged backup site hosted on Google Sites. See the full write-up from BleepingComputer via the source link for quotes and complete context.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Custom ChatGPTs push ClickFix attacks: why it matters now
The malicious custom GPTSource: Huntress However, the page shows a fake Cloudflare check and instructs visitors to run a PowerShell command, which deploys the infection chain. Huntress researchers observed similar attacks in the past, which used deceptive ChatGPT conversations to launch ClickFix ruses and compromise targets, but using custom GPTs is a novel approach.
Custom ChatGPTs push ClickFix attacks: who is affected
In both attacks, the malicious instructions are hosted on the legitimate ChatGPT.com domain, lending legitimacy to the operation and increasing the chances the victim will follow the instructions. If executed locally, the provided PowerShell command installs a malicious MSI that launches a legitimate, signed application and a modified DLL loading the malware.
Custom ChatGPTs push ClickFix attacks: what to watch
The payload used in this campaign is a remote access trojan (RAT) with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads. See the full write-up from BleepingComputer via the source link for quotes and complete context.
Developer Action Items
- β Diff the official changelog for OpenAI / ChatGPT / Google 5.6 before you bump β APIs, defaults, and removed flags only.
- β Install through the vendor's documented channel in staging; keep a one-command rollback and time-box the canary.
- β Grep your repo for old flag names, lockfile pins, and plugin versions that the notes mark as breaking.
- β Prefer the first patch cut over the day-zero tag unless you have a reason to be on the leading edge.
- β If BleepingComputer did not name a region, plan, or SKU, screenshot the official availability line before you promise it to users.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Bring near-Astra intelligence to everyday work with GPT-6.1 Sol on Amazon Bedrock
Read β
Accelerating agentic RL and evaluation research velocity with 45x faster GKE Agent Sandbox
Read β
Google is a technology partner for the launch of America.gov.
Read β
Introducing Threat Signals: agentic skills for open-source threat intelligence, free forβ¦
Read β
Today's Tech Pulse briefing
Full briefing β
Advertisement