Security firm Huntress has reported that it has identified attacks exploiting ChatGPT's "Custom GPTs" to direct users to websites that lead to malware infections.
Attacks Exploiting ChatGPT "Custom GPTs" to Lure Users into Malware Infections Leverage the Trust of Legitimate Domains
This article is a translation. Read the Japanese original
Attackers are using Custom GPTs running on the legitimate chatgpt.com domain, disguising them as authentic ChatGPT models. Specifically, a method has been confirmed where attackers use names like "Plus 5.6" to provide users with a sense of security that they are using a legitimate service, thereby luring them to external websites.
The landing pages on Google Sites display a screen mimicking the Cloudflare CAPTCHA authentication interface. At that point, users are instructed to "paste and execute a PowerShell command on Windows" to resolve the issue. This series of tactics, where users are tricked into executing commands themselves, is known as "ClickFix."
If a user follows these instructions, a malicious MSI-format installer is executed via an obfuscated PowerShell script. According to Huntress's analysis, this infection path follows a complex eight-stage process, utilizing techniques such as "DLL Side-loading," which forces a legitimate executable to load a malicious DLL.
Once a PC is infected, a RAT (Remote Access Trojan) is installed. This malware is equipped with functions to investigate device settings, installed software, and hardware information. Huntress warns that attackers are exploiting highly trusted services like ChatGPT and Google Sites as entry points for social engineering.
Sources
- ChatGPTの「カスタムGPT」を悪用してマルウェア感染へ誘導する攻撃、正規のChatGPTページを入口に利用 (GIGAZINE、2026-10-01)