A fake ChatGPT experience is turning a Windows action into malware. Attackers are using malicious Custom GPTs to steer users toward a fake verification page that ends with PowerShell execution and a remote access trojan.
The campaign relies on social engineering rather than a software exploit. Victims are sent from ChatGPT to a Google Sites page posing as a Cloudflare CAPTCHA, where they are told to run a command that launches the ClickFix malware chain.
Huntress researchers tied at least 40 incidents to the Google Sites infrastructure, including two confirmed infections that began through malicious Custom GPTs. After Huntress contacted OpenAI, the first identified GPT had been taken down as of Sept. 25, 2026; researchers found a replacement on Sept. 27 that installed the same RAT through a modified delivery chain.
How the ClickFix chain unfolds
In some incidents, victims searching Google for “chatgpt” clicked a sponsored result that led to an attacker-created Custom GPT named “Plus 5.6,” which Huntress said was designed to resemble a legitimate ChatGPT offering. Paid advertising has appeared in other ClickFix campaigns, including a HBO Max Reddit advertising account that researchers said was compromised and used to push malicious ads.
The GPT displayed a fake “Service Availability Notice” that sent users to a Google Sites page impersonating a Cloudflare CAPTCHA, where they were instructed to execute a Windows command.
Microsoft has documented ClickFix campaigns that persuade victims to run commands through Windows Run, Terminal, or PowerShell instead of relying on a malicious attachment or exploit. Other variants have targeted macOS, including a campaign using browser fingerprinting across more than 250 ClickFix domains to hide lures from scanners.
In this campaign, PowerShell downloaded an obfuscated script that installed a malicious MSI and began an eight-stage infection chain. The first version abused a legitimate Canon-signed application for DLL sideloading and established persistence through a Run key and scheduled task.
The replacement switched to Stardock’s signed DeElevate64.exe, moved the loader from a WAV file into a Microsoft NuGet package, and stripped Mark-of-the-Web from the MSI. Huntress said the final RAT was identical at the binary level to the first version.
The RAT supports remote desktop access, screen monitoring, camera and audio capture, file searching, host reconnaissance, and follow-on payload execution. It also uses DNS over HTTPS through Cloudflare, Google, and Quad9 to discover command-and-control infrastructure.
Layered defenses can disrupt ClickFix
Attackers can swap domains, signed applications, and payload wrappers quickly, so defenses should prioritize behavior over single indicators. Investigators used a similar approach to link rotating MacSync infrastructure through repeated endpoint and network behavior.
Organizations can reduce exposure by:
- Train users to treat verification pages that request PowerShell, Terminal, or Windows Run commands as malicious.
- Restrict PowerShell and other script interpreters where they are not required, and use application-control or attack-surface-reduction rules to block suspicious execution.
- Monitor for PowerShell spawning
msiexec, signed applications running from unexpected%LOCALAPPDATA%paths, and Run keys or scheduled tasks that recreate persistence. - Enable PowerShell script block logging and retain telemetry for investigation.
- Isolate systems where users executed a suspected ClickFix command and investigate persistence and follow-on access before returning them to service.
- Test incident response plans against ClickFix-style initial access, including host isolation, credential resets, persistence hunting, and endpoint recovery.
Attackers can change delivery components while preserving the same core behavior. Behavioral detection, endpoint hardening, and rehearsed response procedures are more durable than blocking one malicious GPT, URL, or payload hash.
Read more: Attackers are also using AI agents to accelerate credential harvesting and other attack stages, adding more pressure on defenders to shorten detection and response times.





