A Custom GPT was used to draw users into a ClickFix campaign that ultimately installed remote access trojan (RAT) malware on victims’ devices. The lure was hosted on the legitimate ChatGPT website and presented as a community-built GPT called “Plus 5.6,” a name that could easily be mistaken for an official ChatGPT model.
Huntress investigated at least 40 incidents tied to the Google Sites domain and confirmed two that began through a Custom GPT. The first GPT was removed after being reported to OpenAI, but another linked to the campaign appeared two days later. Here is how the campaign worked and what happened after victims followed the ClickFix prompt.
How the ChatGPT ClickFix Attack Worked
The Custom GPT attack followed a three-stage social-engineering flow before any malware was installed:
Stage 1: Sponsored Google Result Led to the Custom GPT
In some incidents, victims searching Google for “chatgpt” clicked a sponsored result that opened the “Plus 5.6” Custom GPT on the legitimate chatgpt.com domain. Google Ads tracking parameters indicated that paid ads were being used to drive traffic to the page. The page itself identified the GPT as being from a “community builder,” rather than presenting it as an OpenAI-created model.
Stage 2: “Plus 5.6” Sent Users to a Backup Site

Source: Huntress
When users interacted with the GPT, it returned a “Service Availability Notice” claiming that the primary domain was experiencing limited availability. It then offered two options: upgrade to ChatGPT Plus or continue using the service through a supposed backup domain. That backup link led away from ChatGPT to a page hosted on Google Sites, which formed the next part of the attack chain.
Stage 3: Fake Verification Started the ClickFix Attack
The Google Sites page displayed a ChatGPT and Cloudflare-branded verification screen. Instead of a normal CAPTCHA, users were told to copy and paste a command that launched PowerShell. Running it started the malware infection, leading to a malicious MSI installer. The findings do not indicate a ChatGPT vulnerability, as the infection began only after the victim followed the ClickFix instructions.
What Happened After the PowerShell Command Was Run?
Once the victim ran the PowerShell command, it downloaded and executed an obfuscated script that silently installed a malicious MSI. In the first version Huntress analyzed, the installer launched a legitimate Canon-signed application and abused DLL sideloading to load malicious code. It also set up two persistence mechanisms to keep the malware active on the device.
The infection chain was unusually long for a ClickFix attack. Huntress noted, “Most ClickFix chains we see are two or three hops: paste a command, download something, run it. This one has eight, and each hop exists to hide the next one.” Once active, the RAT gave attackers a wide range of control over the infected device. It could:
- Search files across the device
- Capture camera, microphone, and system audio
- Run remote desktop sessions and view the screen
- Download and execute additional payloads in several formats
- Collect information about antivirus software, network adapters, open ports, installed software, and hardware
How to Protect Yourself from ClickFix Attacks
A few simple checks can help you spot the warning signs before the attack gets any further:
- Do not run commands to complete a CAPTCHA: If a verification page asks you to open PowerShell, Command Prompt, Terminal, or the Windows Run dialog, stop and close the page.
- Check who created a Custom GPT: Look for the creator information before trusting the GPT, especially if it is presented like an official OpenAI tool or model.
- Do not assume a sponsored result is official: Check the destination URL before opening it, or go directly to the service’s known website instead of relying on the first paid result.
- Be cautious with unexpected backup domains: If a service suddenly sends you to another domain, verify the address independently before following any instructions there.
If you already ran the command, disconnect the affected device from the network and run a full or offline malware scan.
Closing Thoughts
The campaign is a reminder that attackers do not always need to imitate legitimate services from scratch. In this case, they used a real platform like ChatGPT to carry victims further into the attack, with the step that triggered the infection only appearing once users were asked to run a command themselves.







