Invest1 publisher2 min readPublished
Fake custom GPTs on chatgpt.com open an eight-stage ClickFix malware chain
Huntress traced at least two of more than 40 ClickFix malware incidents to fake custom GPTs on OpenAI's chatgpt.com. On that route every hop before the PowerShell command sat on a Google or OpenAI address, so staff taught to trust familiar domains would click through each one.
The Investor · Invest desk
What happened
- People searching Google for "chatgpt" were often served sponsored results that led to the attacker-built GPTs on OpenAI's own domain.
- The GPTs steered conversations toward a Google Sites page posing as a Cloudflare CAPTCHA that told victims to run a PowerShell command.
- That command fetched an MSI installer that deployed a remote access trojan with remote desktop control, audio and video capture, and a way to drop more payloads.
- OpenAI took down the first identified malicious GPT on September 25, 2026, and a second malicious GPT appeared on September 27.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Removing GPTs one at a time leaves the recurring cleanup cost with OpenAI, while the attacker's cost to return is one more GPT built from the same playbook.
- exposure Google sold the sponsored "chatgpt" results that fed victims in and hosted the fake CAPTCHA page, so its ad verification now draws the same scrutiny as OpenAI's GPT publishing.
- decision Teams that allow chatgpt.com wholesale have to choose between restricting a tool staff use and moving detection to endpoints, watching for PowerShell that calls decimal IPs or pulls MSI installers.
In some variants, the first address in the chain that belongs to neither Google nor OpenAI turns up inside the PowerShell command itself, written as the integer 1614733393 [6][3]. Converted, that is 96.62.224.81 (96 times 16,777,216, plus 62 times 65,536, plus 224 times 256, plus 81) [5]. The decimal form is a known way to get an address past casual inspection and some URL filtering tools [6].
The attackers' visible outlay is the sponsored placement for "chatgpt" [2]. The report does not say what it cost them. On the defending side, the only removal interval on record is two days, from OpenAI's first takedown to the appearance of the next malicious GPT [1]. Crypto Briefing, which reported Huntress's findings, read that speed as a sign the attackers had a repeatable playbook for spinning up new instances [9].
Huntress's count supports two readings. The firm, which found the campaign in late September 2026 [1], linked more than 40 incidents through the campaign's Google Sites infrastructure and traced at least two of them directly to the fake GPTs [7]. On the published minimums, that works out to about one in twenty [2]. On the first reading, chatgpt.com is a side entrance, and the stage every linked case shared was the Google Sites page asking for the PowerShell command [4]. On the second, "at least two" is a floor, and more of the infections began on a fake GPT than investigators could confirm.
I think the domain problem is real and runs wider than OpenAI. Google Sites is as familiar a name as chatgpt.com, and it is the host common to every incident Huntress linked [4]. The act that installed the trojan was the victim pasting and running a command, with no attachment to scan and no executable to flag [10]. A training rule aimed at that request, treating any CAPTCHA that asks for a pasted command as an attack, would stop the chain at the page all 40-plus cases shared [4].
The view is wrong if a fuller trace shows most of the 40-plus incidents starting on chatgpt.com. The exposure would then be OpenAI's open GPT publishing, where any user can create a GPT that redirects visitors to malicious infrastructure [11], and allow-list policy would be the right place for the fix.
What to watch
- Whether OpenAI adds review before custom GPTs go live, beyond removing malicious ones after they are found.
- Whether Google restricts sponsored results on the search term "chatgpt", the route that fed victims to the fake GPTs.
- How quickly further replacement GPTs appear after the September 27 instance, and whether that interval stays near two days.