Cybercriminals Exploit ChatGPT Custom GPTs to Funnel Victims into ClickFix Malware Traps
Security researchers have uncovered a new abuse vector in which threat actors deploy custom ChatGPT extensions to masquerade as legitimate product listings, then steer unsuspecting users toward malicious sites that employ ClickFix lures to install remote‑access trojans.
OpenAI's Custom GPT feature lets developers publish tailored conversational agents that appear in the ChatGPT marketplace. Because the platform handles hosting and distribution, these bots can reach a broad audience with minimal effort, making them attractive to both legitimate creators and malicious actors seeking a veneer of credibility.
The lures in question rely on a classic social‑engineering trick: a pop‑up or banner promising a quick fix for a perceived problem, such as a browser error or a system slowdown. When users click the offered “fix,” they are redirected to a payload server that silently drops a Remote Access Trojan (RAT), granting attackers persistent control over the compromised machine.
Huntress, a threat‑detection firm, first observed the campaign in late September 2026. Analysts noted that the malicious custom GPTs consistently referenced product names and pricing details that mirrored legitimate software vendors, then embedded links that resolved to domains hosting the ClickFix pages. The pattern was identified through a combination of endpoint telemetry and network‑traffic analysis, revealing a coordinated effort to blend AI‑generated content with classic malware distribution techniques.
The emergence of this tactic highlights a growing convergence between AI platforms and traditional cyber‑crime infrastructure. While OpenAI has instituted review processes for custom bots, the sheer volume of submissions makes exhaustive vetting challenging. Security experts warn that users should treat any unsolicited product recommendation from a conversational AI with the same skepticism applied to email phishing attempts.
Moving forward, industry observers expect tighter scrutiny of AI‑generated links and greater collaboration between platform providers and security firms. In the meantime, organizations are advised to reinforce endpoint protection, educate staff about the risks of clicking on unexpected “fix” prompts, and monitor network traffic for connections to known ClickFix domains.
Comments (0)
Be the first to comment.
Join the discussion