Hackers Weaponize Custom GPTs for ClickFix Malware Attacks

Hackers Weaponize Custom GPTs for ClickFix Malware Attacks

By leveraging legitimate third-party extensions, threat actors have found a way to amplify the credibility of traditional social engineering tactics to an alarming degree. The emergence of sophisticated campaigns in early 2026 demonstrated that the trust users place in established AI ecosystems like OpenAI is being systematically dismantled. Rather than relying on suspicious external domains or unsolicited email attachments, attackers successfully integrated their malicious infrastructure directly into the chatgpt.com environment through the Custom GPT feature. One prominent example involved an assistant named Plus 5.6, which presented itself as a high-performance productivity tool but served as a gateway for the ClickFix malware delivery system. This evolution in cybercrime highlights a transition from technical vulnerabilities to the exploitation of platform-granted legitimacy. Users, accustomed to interacting with AI for daily tasks, are less likely to question instructions coming from a domain they visit multiple times a day for legitimate work purposes.

The ClickFix Methodology: Exploiting User Interaction

The central mechanism of the ClickFix attack involves a deceptive multi-stage process designed to bypass modern security filters by moving the burden of execution onto the human user. When a victim interacted with the malicious Custom GPT, they were redirected to a series of Google Sites pages meticulously crafted to mimic official Cloudflare CAPTCHA verification screens. These pages utilized familiar branding and layouts to convince the target that a routine security check was necessary to proceed with the AI service. Instead of a simple checkbox or image recognition task, the interface prompted the user to copy and execute a specific PowerShell command within their system terminal. This social engineering masterstroke effectively bypassed automated email and web gateways that typically scan for static malicious files. By convincing the user that they were performing a necessary technical fix, the attackers ensured the malicious script entered the system through a manual action. This bypass shifted the focus of defense.

Once the PowerShell command was executed, it initiated a complex eight-stage infection chain that prioritized stealth and persistence on the compromised machine. This sequential process involved downloading several intermediate payloads, each responsible for decrypting and launching the next stage while checking for the presence of sandboxes or virtual machine environments. The final payload of this campaign was a sophisticated remote access trojan that granted the attackers comprehensive control over the victim’s hardware and data. This malware possessed the capability to capture audio and video feeds, record keystrokes, and manage files via a remote desktop interface. Furthermore, the trojan functioned as a staging point for secondary infections, allowing the threat actors to deploy ransomware or data exfiltration tools depending on the value of the target. This level of access underscored the high stakes of falling for what initially appeared to be a simple prompt. The multi-stage nature of the attack made it quite difficult to analyze.

Strategic Distribution: Technical Obfuscation and Trust

The success of these attacks was largely driven by the clever use of distribution channels that prioritized high visibility and apparent legitimacy. Attackers utilized sponsored Google search results for common terms like chatgpt to ensure their malicious links appeared at the top of search engine results pages. This method capitalized on the habit of users clicking the first available link when searching for official tools, leading them directly to the weaponized GPT instances. By hosting the entry point of the attack on the actual OpenAI domain, the actors successfully bypassed URL filtering tools that automatically block known malicious websites. This tactic essentially hijacked the reputation of the platform, making it nearly impossible for traditional perimeter defenses to distinguish between a legitimate AI assistant and a malicious one. To further evade detection, the campaign employed advanced obfuscation techniques, including the use of decimal-encoded IP addresses that bypassed signature-based detection systems.

The ClickFix campaign demonstrated significant gaps in how search engines verified advertisements and how AI platforms monitored custom content. Security experts recommended that organizations focused on educating employees about the dangers of copying commands into terminal windows, regardless of the perceived legitimacy of the source. It was concluded that behavioral analysis of PowerShell execution patterns remained the most effective defense against such multi-stage social engineering attempts. Moving forward, the synthesis of these findings suggested that as AI platforms evolved, they provided a new and highly credible trust amplifier for traditional attack vectors. Researchers emphasized that the ultimate solution involved a combination of better platform-level vetting and robust endpoint protection. Organizations that adopted a more proactive stance on monitoring user-generated tool interactions were better positioned to mitigate these risks. This era of cyber threats required a fundamental change in how the concept of a trusted domain was defined.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address