Malicious Custom GPTs Lure Windows Users Into ClickFix Malware

Attackers are abusing Custom GPTs to lure Windows users into ClickFix malware chains that end in PowerShell execution and a remote access trojan.

Oct 5, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A fake ChatGPT experience is turning a Windows action into malware. Attackers are using malicious Custom GPTs to steer users toward a fake verification page that ends with PowerShell execution and a remote access trojan.

The campaign relies on social engineering rather than a software exploit. Victims are sent from ChatGPT to a Google Sites page posing as a Cloudflare CAPTCHA, where they are told to run a command that launches the ClickFix malware chain.

Huntress researchers tied at least 40 incidents to the Google Sites infrastructure, including two confirmed infections that began through malicious Custom GPTs. After Huntress contacted OpenAI, the first identified GPT had been taken down as of Sept. 25, 2026; researchers found a replacement on Sept. 27 that installed the same RAT through a modified delivery chain.

How the ClickFix chain unfolds

In some incidents, victims searching Google for “chatgpt” clicked a sponsored result that led to an attacker-created Custom GPT named “Plus 5.6,” which Huntress said was designed to resemble a legitimate ChatGPT offering. Paid advertising has appeared in other ClickFix campaigns, including a HBO Max Reddit advertising account that researchers said was compromised and used to push malicious ads.

The GPT displayed a fake “Service Availability Notice” that sent users to a Google Sites page impersonating a Cloudflare CAPTCHA, where they were instructed to execute a Windows command.

Microsoft has documented ClickFix campaigns that persuade victims to run commands through Windows Run, Terminal, or PowerShell instead of relying on a malicious attachment or exploit. Other variants have targeted macOS, including a campaign using browser fingerprinting across more than 250 ClickFix domains to hide lures from scanners.

In this campaign, PowerShell downloaded an obfuscated script that installed a malicious MSI and began an eight-stage infection chain. The first version abused a legitimate Canon-signed application for DLL sideloading and established persistence through a Run key and scheduled task.

The replacement switched to Stardock’s signed DeElevate64.exe, moved the loader from a WAV file into a Microsoft NuGet package, and stripped Mark-of-the-Web from the MSI. Huntress said the final RAT was identical at the binary level to the first version.

The RAT supports remote desktop access, screen monitoring, camera and audio capture, file searching, host reconnaissance, and follow-on payload execution. It also uses DNS over HTTPS through Cloudflare, Google, and Quad9 to discover command-and-control infrastructure.

Advertisement

Layered defenses can disrupt ClickFix

Attackers can swap domains, signed applications, and payload wrappers quickly, so defenses should prioritize behavior over single indicators. Investigators used a similar approach to link rotating MacSync infrastructure through repeated endpoint and network behavior.

Organizations can reduce exposure by:

  • Train users to treat verification pages that request PowerShell, Terminal, or Windows Run commands as malicious.
  • Restrict PowerShell and other script interpreters where they are not required, and use application-control or attack-surface-reduction rules to block suspicious execution.
  • Monitor for PowerShell spawning msiexec, signed applications running from unexpected %LOCALAPPDATA% paths, and Run keys or scheduled tasks that recreate persistence.
  • Enable PowerShell script block logging and retain telemetry for investigation.
  • Isolate systems where users executed a suspected ClickFix command and investigate persistence and follow-on access before returning them to service.
  • Test incident response plans against ClickFix-style initial access, including host isolation, credential resets, persistence hunting, and endpoint recovery.

Attackers can change delivery components while preserving the same core behavior. Behavioral detection, endpoint hardening, and rehearsed response procedures are more durable than blocking one malicious GPT, URL, or payload hash.

Read more: Attackers are also using AI agents to accelerate credential harvesting and other attack stages, adding more pressure on defenders to shorten detection and response times.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.