Malicious Custom GPT on chatgpt.com Lures Users into Installing a Remote Access Trojan
What Happened – Attackers created a sponsored Google result for a ChatGPT Custom GPT called “Plus 5.6”. The custom GPT redirects users to a fake Cloudflare CAPTCHA on a Google Sites page, then delivers a ClickFix command that, when copied into a terminal, installs a signed remote‑access trojan (RAT). Huntress reports at least 40 incidents, with dozens of users infected.
Why It Matters for Trust & Control Assurance
- The campaign exploits the trust users place in platform‑hosted content, highlighting the need for continuous security‑awareness training and documented user‑behavior controls.
- Execution‑policy gaps (e.g., unrestricted Run dialog or PowerShell) allow a single copy‑paste command to bypass defenses; a control‑assurance program must capture such policy violations as evidence.
- Monitoring of third‑party content (custom GPTs, sponsored ads) and logging of command‑line activity provide a defensible audit trail that satisfies the “Identify” and “Protect” functions of NIST CSF 2.0.
Who Is Affected – Enterprises and SaaS users that rely on OpenAI’s ChatGPT platform, spanning technology, finance, healthcare, and any organization where employees query AI assistants.
Recommended Actions
- Enforce endpoint execution controls: block or restrict the Win + R dialog, PowerShell, and other command‑line interfaces for standard users.
- Deploy regular security‑awareness simulations that include “copy‑and‑paste” phishing (ClickFix) scenarios.
- Enable logging of command‑line activity and integrate alerts into a continuous control‑monitoring dashboard.
Technical Notes – The attack uses a sponsored Google Search ad → malicious Custom GPT on chatgpt.com → fake Cloudflare CAPTCHA on Google Sites → ClickFix command → signed Canon/Stardock executable delivering a full‑featured RAT. Source: Help Net Security