Fake custom GPTs on chatgpt.com open an eight-stage ClickFix malware chain
Huntress traced at least two of more than 40 ClickFix malware incidents to fake custom GPTs on OpenAI's chatgpt.com. On that route every hop before the PowerShell command sat on a Google or OpenAI address, so staff taught to trust familiar domains would click through each one.
Reality
- Evidence45
- Adoption20
- Hype gap+20
- Incentives
- Insufficient
- Confidence50