Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Legion of Honour: Police investigate corruption claims for France’s top award

    September 29, 2026

    Budget : comment Matignon compte durcir l’accès des étrangers aux APL et allocations familiales – POLITICO

    September 29, 2026

    South West Water fined £8m for hundreds of sewage spills in Cornwall and Devon | Pollution

    September 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Legion of Honour: Police investigate corruption claims for France’s top award
    • Budget : comment Matignon compte durcir l’accès des étrangers aux APL et allocations familiales – POLITICO
    • South West Water fined £8m for hundreds of sewage spills in Cornwall and Devon | Pollution
    • Meta’s Muse AI sent a YouTuber’s address to a stranger
    • Catch threats before they escalate with real-time Identity Telemetry
    • André Dragosch: Why Bitcoin’s Fair Value Is $197,000
    • NASA’s Crew-13 could go from Florida to the ISS in under 9 hours
    • In war-torn South Sudan, giraffes retain a surprisingly healthy gene pool
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 29, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A newly discovered ClickFix campaign is relying on ChatGPT Custom GPTs to impersonate legitimate products and lure victims into executing malicious code on their machines.

    Custom GPTs are personalized versions of ChatGPT that may include specific instructions and tools. They are hosted on ChatGPT.com, and their pages feature their custom names at the top, along with the builder’s profile.

    As part of the malicious campaign, a threat actor programmed two Custom GPTs to respond to users’ prompts with a Google Sites link leading to a ClickFix page, cybersecurity firm Huntress reports.

    On this page, visitors were instructed to execute PowerShell commands that downloaded a malicious MSI file as part of a multi-stage infection chain.

    According to Huntress, at least 40 users have been infected as part of the campaign, and at least two of the incidents are connected to a Custom GPT instance. OpenAI took down the Custom GPT on September 25, but a second one was discovered on September 27.

    “Threat actors are finding success in this specific abuse of Custom GPTs for social engineering and are continuing to rely on this technique,” Huntress notes.

    Advertisement. Scroll to continue reading.

    The victims accessed the Custom GPT after searching for ChatGPT on Google and being served the page as a sponsored result at the top of the search results.

    To trick the victims, the attackers titled the Custom GPT “Plus 5.6” and claimed it was from a “community builder”. The user received a fake notice claiming limited availability through the primary domain and requesting an upgrade or use of the service through a backup domain.

    Hosted on a Google Sites page, the fake backup domain would serve a Cloudflare CAPTCHA check, part of the ClickFix attack, instructing the victim to execute a PowerShell command meant to download and execute a malicious installer.

    The first Custom GPT served an installer that abused a legitimate Canon-signed application for DLL sideloading and set up persistence through a User Run key and a scheduled task posing as “Canon Configuration Reader”.

    The infection chain continued with a loader concealed as an audio file, designed to bypass security protections, perform system checks, and display a fake loading window.

    At the next stage, malicious code was loaded from a heavily obfuscated audio file containing a custom archive with 315 folders and 806 files inside, including the final payload, a RAT capable of fetching, processing, and executing various types of payloads.  

    The malware fingerprinted the infected system and connected to its command-and-control (C&C) server using DNS-over-HTTPS through Cloudflare, Google, and Quad9.

    While the final payload served by the second Custom GPT remained unchanged, the threat actor switched to a Stardock executable and a patched Stardock DLL for infection, and placed the loader in a Microsoft NuGet package instead of an audio file.

    Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    Related: RatHat Android Trojan Uses AI for Automation

    Related: US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

    attacks ChatGPT ClickFix custom GPTs hackers
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Catch threats before they escalate with real-time Identity Telemetry

    Reco Raises $55 Million for Agentic Security

    Vietnamese man charged in $16 million ‘pig butchering’ crypto scam

    Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

    Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

    Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Legion of Honour: Police investigate corruption claims for France’s top award

    September 29, 2026

    Budget : comment Matignon compte durcir l’accès des étrangers aux APL et allocations familiales – POLITICO

    September 29, 2026

    South West Water fined £8m for hundreds of sewage spills in Cornwall and Devon | Pollution

    September 29, 2026

    Meta’s Muse AI sent a YouTuber’s address to a stranger

    September 29, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Legion of Honour: Police investigate corruption claims for France’s top award

    September 29, 2026

    Budget : comment Matignon compte durcir l’accès des étrangers aux APL et allocations familiales – POLITICO

    September 29, 2026

    South West Water fined £8m for hundreds of sewage spills in Cornwall and Devon | Pollution

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.