Fake ChatGPT Custom GPT ads push ClickFix RAT malware
Huntress found Google ads for 'chatgpt' leading to a malicious Custom GPT on chatgpt.com that ends in a ClickFix RAT. Bookmark your AI tools; stop searching.
Your team types "chatgpt" into Google a dozen times a day. Huntress found attackers buying that search. A sponsored ad led to a malicious Custom GPT hosted on the real chatgpt.com, and from there to a ClickFix page that installs a remote access trojan. The domain was real. The ad slot was real. The malware was real too.
What actually happened
Per the Huntress write-up, published September 28:
- The lure. Sponsored Google results for "chatgpt" linked to a Custom GPT named "Plus 5.6," built to look like an official model.
- The handoff. The GPT showed a fake "service availability notice" and pointed users to a "backup domain" on Google Sites. That page imitated a Cloudflare CAPTCHA check.
- The ClickFix step. The fake check told victims to paste a PowerShell command. The command downloaded an MSI that sideloaded malware through legitimately signed Canon and, in a second version, Stardock executables.
- The payload. A RAT with remote desktop, screen capture, camera and microphone recording, browser data targeting, file search and the ability to run more payloads. It hides command traffic in DNS-over-HTTPS.
- Scale. Huntress responded to at least 40 incidents tied to the campaign's Google Sites page. Two of them it confirmed started at the Custom GPT.
- Takedown. OpenAI removed "Plus 5.6" on September 25 after Huntress reported it. A replacement with the same name appeared two days later and was still live when Huntress published.
Why it matters for your business
"Check the domain" is no longer enough. We have told clients for years to look at the URL. Here the first two hops were chatgpt.com and sites.google.com. User-generated content on trusted platforms beats that rule.
Ads are the entry point. Your staff do not need to search for tools they use every day. Bookmark ChatGPT, Claude, Gemini and your other AI tools, or push them through your browser management. A sponsored result for a tool you already pay for is a red flag.
No real CAPTCHA asks you to run a command. That is the whole ClickFix trick, and it keeps working. If you can, block PowerShell for non-admin users and alert when PowerShell launches msiexec from the temp folder, which is one of the red flags Huntress lists.
Key takeaways
- Google ads for "chatgpt" led to a malicious Custom GPT on the real chatgpt.com
- A fake CAPTCHA then told users to paste PowerShell, which installed a RAT
- Huntress tied at least 40 incidents to the campaign; two started at the GPT
- OpenAI took down the first GPT; a copy came back two days later
- Bookmark your AI tools, ignore sponsored results, and restrict PowerShell
Rolling out AI tools to your team without a security baseline? We set up AI tooling with managed bookmarks, locked-down endpoints and access you can audit. Talk to us about your setup.
Sources: Huntress, Help Net Security.
- #chatgpt
- #clickfix
- #malware
- #phishing
- #security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
AI writing tells: Opus 5.5 says 'this matters' 116x too often
Graphite's AI writing tells study finds Claude Opus 5.5 dropped the em-dash but overuses 'this matters' 116x. Every model has new tells. Edit for patterns, not words.
Read itFideuram €95M AI voice-clone fraud: verify every payment
A cloned lawyer's voice and a spoofed CEO WhatsApp moved €95M out of Italian bank Fideuram. Here's the payment-verification rule a small business needs.
Read it