ChatGPT Malware Alert: Hackers Weaponize Custom GPTs to Hijack PCs

ChatGPT
Screenshot

The era of identifying cyber threats solely by misspelled URLs and aggressive pop-ups is fading, as threat actors increasingly weaponize the implicit trust users place in top-tier domains. Security researchers at Huntress have uncovered a sophisticated malware campaign that leverages OpenAI’s official website to deceive victims, utilizing a malicious Custom GPT to distribute a dangerous remote-access trojan.

Hackers exploited OpenAI’s Custom ChatGPT feature to host a fraudulent chatbot dubbed “Plus 5.6.” Because Custom GPTs operate directly on the official ChatGPT.com domain, the malicious bot appeared entirely legitimate to the naked eye. To drive traffic, the attackers occasionally utilized sponsored Google Search results, pushing their malicious link above genuine ChatGPT queries.

Regardless of the prompt a user entered, the Plus 5.6 bot delivered a pre-programmed response claiming that ChatGPT was experiencing server outages. It then directed the user to a “backup domain” to continue their session. This link routed victims to a fraudulent Google Sites webpage meticulously designed to mimic a standard Cloudflare anti-bot security check.

ChatGPT

At this stage, the attackers deployed a social engineering tactic known as ClickFix. Rather than relying on background software exploits, the ClickFix method tricks victims into executing the attack themselves. The fake verification screen instructed users to prove they were human by copying a provided command and pasting it directly into their Windows terminal.

ChatGPT

Executing this command silently triggered the installation of a Remote Access Trojan (RAT). This severe payload grants attackers near-total control over the infected machine. Once entrenched, the hackers can monitor the screen, exfiltrate private files, hijack the system’s microphone and webcam, and silently deploy additional malware.

Huntress traced at least 40 security incidents back to the fraudulent Google Sites domain, confirming that several infections originated directly from the malicious Custom GPT. While OpenAI removed the initial bot in late September, researchers identified a replacement linked to the same operation just two days later. The incident highlights a growing trend among cybercriminals who are exploiting the immense public trust in emerging AI platforms to execute attacks that bypass standard visual scrutiny.

Tags:,