Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Malicious Custom GPT on chatgpt.com Lures Users into Installing a Remote Access Trojan

Attackers leveraged a sponsored Google result for a ChatGPT Custom GPT to deliver a fake CAPTCHA that prompted users to copy‑paste a command, installing a signed remote‑access trojan. The incident underscores the need for security‑awareness training and execution‑policy controls to maintain audit‑ready evidence of user‑behavior safeguards.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Malicious Custom GPT on chatgpt.com Lures Users into Installing a Remote Access Trojan

What Happened – Attackers created a sponsored Google result for a ChatGPT Custom GPT called “Plus 5.6”. The custom GPT redirects users to a fake Cloudflare CAPTCHA on a Google Sites page, then delivers a ClickFix command that, when copied into a terminal, installs a signed remote‑access trojan (RAT). Huntress reports at least 40 incidents, with dozens of users infected.

Why It Matters for Trust & Control Assurance

  • The campaign exploits the trust users place in platform‑hosted content, highlighting the need for continuous security‑awareness training and documented user‑behavior controls.
  • Execution‑policy gaps (e.g., unrestricted Run dialog or PowerShell) allow a single copy‑paste command to bypass defenses; a control‑assurance program must capture such policy violations as evidence.
  • Monitoring of third‑party content (custom GPTs, sponsored ads) and logging of command‑line activity provide a defensible audit trail that satisfies the “Identify” and “Protect” functions of NIST CSF 2.0.

Who Is Affected – Enterprises and SaaS users that rely on OpenAI’s ChatGPT platform, spanning technology, finance, healthcare, and any organization where employees query AI assistants.

Recommended Actions

  • Enforce endpoint execution controls: block or restrict the Win + R dialog, PowerShell, and other command‑line interfaces for standard users.
  • Deploy regular security‑awareness simulations that include “copy‑and‑paste” phishing (ClickFix) scenarios.
  • Enable logging of command‑line activity and integrate alerts into a continuous control‑monitoring dashboard.

Technical Notes – The attack uses a sponsored Google Search ad → malicious Custom GPT on chatgpt.com → fake Cloudflare CAPTCHA on Google Sites → ClickFix command → signed Canon/Stardock executable delivering a full‑featured RAT. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/29/malicious-chatgpt-custom-gpt-malware-via-clickfix/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →