Security1 publisher2 min readPublished
Fake 'Plus 5.6' Custom GPT on chatgpt.com routes users to ClickFix malware
Huntress tied at least 40 incidents to one Google Sites ClickFix page, two of them reached through a fake "Plus 5.6" Custom GPT on chatgpt.com. On that route the search ad, the chatbot page and the lure page all sit on Google or OpenAI domains that URL filters trust.
The Watch · Security desk
What happened
- Whatever the user types, the GPT answers with a "Service Availability Notice" telling them to upgrade to Plus or continue through a "backup domain."
- That backup domain is a Google Sites page posing as a Cloudflare CAPTCHA check that tells visitors to copy a command into Terminal.
- OpenAI removed the reported GPT by September 25, and Huntress found a replacement for the same campaign on September 27, still live at publication.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Teams that lean on URL filtering have to add host-side detection for pasted Terminal commands, the installers those commands fetch, and signed binaries loading unfamiliar DLLs.
- constraint Policing Custom GPTs alone reaches a small slice of this campaign, since only two of at least 40 incidents are confirmed as coming through one.
- precedent With a replacement up two days after takedown, reporting a GPT to OpenAI removes one lure while the operators keep the technique running.
The Custom GPT is the lure step. The page that asks for the pasted command lives one hop further out, on Google Sites [11]. The GPT does one thing: it hands over that link, and it passes as an OpenAI model while it does it [8][10]. A Custom GPT page shows its name at the top and the builder's profile underneath [3]. On this one the profile line reads "community builder" [8]. Huntress researchers wrote that the label "is a tip off for someone who understands what a Custom GPT is, but for an unknowing user this page could pass as a normal, everyday ChatGPT conversation with a new model" [9].
Scope needs care. Two confirmed Custom GPT cases out of at least 40 incidents is 5 percent of the minimum count [1]. What the incidents share is the Google Sites domain [4]. Huntress has seen the same pattern on other AI platforms, with attackers using Claude Artifacts and shared ChatGPT conversations to get victims to click malicious links or run Terminal commands [1].
On the Custom GPT route, every hop before execution sits on a Google or OpenAI domain: a sponsored Google result, then chatgpt.com, then sites.google.com [3]. Huntress found Google Ads click-tracking parameters in the landing URL, meaning the operators paid to put the GPT above organic results for "chatgpt" [7]. A filter keyed to domain reputation sees only Google and OpenAI addresses up to that point [3].
The first event on the host is the pasted command [4]. After it come the MSI install and a legitimate Canon-signed binary, COTFileReadApp.exe, loading a malicious DLL [12][13]. Huntress said the sideload is there to evade detection [13]. Its report title calls the final payload a RAT [14].
The campaign started in late September [2]. Huntress reported the GPT to OpenAI and it was down by September 25 [5]. On September 27 Huntress found a replacement tied to the same campaign. Its URL ends in the same "plus-5-6" slug, and it was still active when Huntress published [6]. The turnaround was two days [2]. "Threat actors are finding success in this specific abuse of Custom GPTs for social engineering and are continuing to rely on this technique," Huntress wrote [15].
What to watch
- Whether Google removes the sites.google.com/view/antibot172881 page and the sponsored ads, since that page is the node the 40-plus incidents share.
- Whether OpenAI restricts Custom GPTs that take model-style names like "Plus 5.6" or send users to off-platform domains.
- Whether Huntress or another responder names the RAT family and ties the Canon-signed sideload to a known operator.