AI·News & analysis
Hackers are using malicious custom ChatGPT bots to spread RAT malware
Security researchers found attackers using a fake ChatGPT custom GPT called 'Plus 5.6' to trick users into a ClickFix attack that installs remote access malware.

Security researchers found attackers using a malicious custom GPT called 'Plus 5.6,' hosted directly on OpenAI's own chatgpt.com domain, to spread remote access malware.
That abuses trust in OpenAI's own domain rather than a lookalike site, making it harder for typical phishing awareness training to catch. It's a reminder that platforms hosting user-generated AI tools face the same abuse patterns as app stores and browser extension marketplaces. Removal after the fact doesn't undo damage already done to the people who encountered it first.
What to know
- Security researchers at Huntress found attackers using a malicious custom GPT called 'Plus 5.6,' hosted on OpenAI's own chatgpt.com domain, to trick users into installing malware.
- Victims reached the fake GPT partly through a sponsored Google search result for 'chatgpt,' then were redirected to a fake Google Sites page mimicking a service outage notice.
- The attack uses a ClickFix-style lure, tricking users into running a PowerShell command that downloads a malicious installer disguised as a Canon-signed application.
- The malware delivers a remote access trojan capable of remote desktop control, audio and camera capture, and file searching, with persistence via a task named 'Canon Configuration Reader.'
- Huntress found at least 40 related incidents; OpenAI removed one malicious GPT by September 25, though a second remained active days later.
Attackers found a new way to make a malware trap look trustworthy: build it directly on OpenAI's own domain.
What researchers found
Security researchers at Huntress uncovered a malicious custom GPT, named "Plus 5.6," hosted directly on OpenAI's chatgpt.com domain and used to trick users into installing remote access malware.
- The lure: a fake GPT named to resemble a legitimate ChatGPT model or upgrade.
- The discovery path: some victims reached it through a sponsored Google search result for the word "chatgpt."
- The payload: a full remote access trojan capable of taking control of an infected machine.
The catch: because the GPT lived on OpenAI's own legitimate domain, standard phishing red flags, like checking a URL for a lookalike domain, wouldn't have caught it.
How the attack actually works
The attack follows a ClickFix-style pattern, a social engineering technique that shows victims a fake service notice instructing them to run a command to fix a supposed problem.
When a user interacted with "Plus 5.6," it responded with a fake "Service Availability Notice" claiming limited access on the primary domain, then directed users to a Google Sites page presented as a "backup domain" to continue.
That Google Sites page then displayed another fake security check, instructing visitors to run a PowerShell command supposedly needed to verify their access.
From PowerShell command to full RAT access
Running that PowerShell command triggers a multi-stage infection chain. It downloads a malicious MSI installer that abuses a legitimate, Canon-signed executable to sideload a malicious DLL, ultimately deploying the actual malware payload.
By the numbers: the resulting remote access trojan gives attackers a substantial set of capabilities once installed, including remote desktop control, audio and camera capture, file searching, host reconnaissance, and the ability to execute additional payloads on the infected system.
For persistence, the malware creates both a registry Run key and a scheduled task, both deliberately named "Canon Configuration Reader" to blend in with legitimate printer or scanner software a victim might genuinely have installed.
How many people this actually hit
Huntress identified at least 40 related incidents tracing back to the malicious infrastructure, with at least two separate confirmed custom GPT variants involved in spreading the attack. That's a modest number in absolute terms, but it represents confirmed, investigated infections rather than a theoretical vulnerability, meaning real people had their machines compromised through what looked like an ordinary interaction with a ChatGPT tool.
OpenAI's response so far
OpenAI removed the first identified malicious GPT by September 25, 2026. However, a second variant reportedly remained active for several days afterward, according to Huntress's findings, meaning the removal process didn't fully close the door on the same attack pattern immediately.
Looking further ahead: OpenAI has separately announced plans to retire custom GPTs entirely, with a stated deadline of December 11, 2026. That broader change, unrelated specifically to this malware campaign, would eventually eliminate the exact attack surface this particular scheme relied on, though it leaves a multi-month window during which similar abuse remains possible.
ClickFix isn't new, but it's exploding
The technique behind this attack, tricking users into pasting and running a malicious command themselves, first appeared in late 2023 and early 2024, typically disguised as a fake CAPTCHA check or browser update notice.
How fast it's grown since then: security firm ESET reported a roughly 500% rise in ClickFix detections between late 2024 and mid-2025, and Microsoft has said the technique accounted for as much as 47% of initial network access incidents it tracked in one recent report. State-sponsored hacking groups from North Korea, Iran, and Russia have all adopted the technique in their own operations over the same period, alongside financially motivated criminal groups.
That rapid growth is exactly why security researchers have been watching for ClickFix showing up in new contexts, like AI platforms, rather than staying confined to the fake-CAPTCHA pages where it first became common. This campaign represents the technique adapting to wherever it can find a plausible-looking pretext, in this case, a ChatGPT-branded tool millions of people already trust by default.
Why hosting on OpenAI's own domain matters so much
The core danger of this specific campaign isn't the ClickFix technique itself, which security researchers have documented across many different platforms and contexts. It's specifically that the malicious GPT lived on chatgpt.com, a domain users have every reason to trust by default.
Most phishing awareness training centers on checking whether a URL looks legitimate before trusting it. This attack sidesteps that entire defense, since the URL genuinely was legitimate, OpenAI's own domain, right up until the point a user got redirected off it to the actual malicious Google Sites page. That's a meaningfully harder attack pattern for typical security awareness training to catch.
A broader pattern for AI platforms
This isn't the first time a platform hosting user-generated AI tools has faced this kind of abuse, and it's unlikely to be the last. App stores and browser extension marketplaces have dealt with similar dynamics for years: legitimate-seeming, platform-hosted content that turns out to be malicious, requiring constant moderation rather than a one-time fix.
Why that comparison matters: as more platforms let users build and share custom AI tools, whether GPTs, plugins, or agent configurations, the same trust exploitation becomes available to attackers targeting any of them, not just OpenAI specifically. Platform-level trust, once established, becomes exactly the kind of asset attackers look to borrow rather than build themselves.
Why custom GPTs are actually going away
OpenAI's planned December 11 retirement of custom GPTs isn't a response to this security incident specifically. It reflects a broader architectural shift the company had already been planning: rather than maintaining separate, standalone specialized versions of ChatGPT, OpenAI wants a single ChatGPT experience with a reusable toolbox of skills and connections that can be called on as needed.
What that means practically: custom GPTs are being replaced by a plugin-based architecture combining reusable skills, reference files, connected apps, and optional tool integrations. Existing GPT creators can migrate their instructions and knowledge files into this new plugin format, though sharing settings and user access reportedly don't carry over automatically, and some builders have raised concerns that plugins don't fully replicate the predictable, self-contained environment a dedicated custom GPT provided.
That transition happens to close off this specific attack vector as a side effect, but it wasn't designed as a security fix, meaning similar abuse patterns could plausibly resurface within whatever replaces custom GPTs if the new plugin system isn't moderated with this exact kind of impersonation in mind from the start.
The bottom line
This campaign succeeded specifically by exploiting the trust users place in OpenAI's own domain, a defense most phishing training doesn't account for. With OpenAI already planning to retire custom GPTs by December, this particular attack vector has a defined expiration date, but the underlying pattern, borrowing a trusted platform's legitimacy to deliver malware, will likely resurface wherever the next popular AI tool-hosting platform gains enough users to make the abuse worthwhile.
For now, the practical advice is genuinely simple: treat any AI tool, official-looking domain or not, that asks you to run a command in PowerShell or Terminal with exactly the same suspicion you'd give an unsolicited email attachment from a stranger.
Key facts
- Malicious GPT name
- 'Plus 5.6'
- Attack technique
- ClickFix (fake outage notice, PowerShell command)
- Payload
- Remote access trojan (RAT)
- Incidents found
- 40+ (Huntress)
- OpenAI response
- Removed first GPT by Sept 25; second still active days later
Got questions?
Quick answers, plain wordsWhat is 'Plus 5.6'?
A malicious custom GPT hosted on OpenAI's chatgpt.com domain, named to look like a legitimate ChatGPT model or upgrade, used by attackers to lure victims into a malware chain.
How did people encounter this malicious GPT?
In some cases, victims found it through a sponsored Google search result for 'chatgpt,' which led them to the fake GPT hosted on OpenAI's own legitimate domain.
What is a ClickFix attack?
A social engineering technique that shows victims a fake error or service notice instructing them to run a command, typically PowerShell, to 'fix' the supposed problem, which actually installs malware.
What happens after someone follows the fake instructions?
The PowerShell command downloads a malicious MSI installer that sideloads a malicious DLL through a legitimate, Canon-signed executable, ultimately deploying a remote access trojan with persistence through a scheduled task and registry key both named 'Canon Configuration Reader.'
What can the malware do once installed?
It grants attackers remote desktop access, audio and camera capture capability, file searching and host reconnaissance, and the ability to execute additional payloads on the infected machine.
How many people were affected?
Huntress identified at least 40 related incidents, with at least two confirmed custom GPT variants involved in spreading the malware.
Has OpenAI done anything about it?
OpenAI removed the first identified malicious GPT by September 25, 2026, though a second variant reportedly remained active days later. OpenAI has also said it plans to retire all custom GPTs entirely by December 11, 2026.
How can I protect myself from this kind of attack?
Be skeptical of any GPT or website instructing you to run PowerShell or terminal commands to fix a service issue, and avoid custom GPTs found through sponsored search ads rather than OpenAI's own official listings.
SourcesBleeping Computer
Topics and tagsOpenAI, Cybersecurity, chatgpt, openai
Related stories

ChatGPT can now show you wearing clothes before you buy them
OpenAI launched virtual try-on and a Favorites list in ChatGPT's shopping results worldwide. Upload a photo of yourself and see how a jacket or accessory might look on you.

OpenAI just launched Dots, its answer to Meta's AI agent that's had investors buzzing all month
OpenAI unveiled Dots at DevDay, always-on AI agents with their own cloud computer, three weeks after Meta's Muse agent helped send Meta stock up 29% this month.

Three tech workers made ChatGPT drive a real Toyota Corolla
A Bay Area side project called DrivingBench wired four AI chatbots into a rented Corolla's steering, gas and brakes, then asked them to drive through a cone course. Only one finished.
More in brief
- California will fine robotaxi companies that block first responders for over 30 minutesOct 2
- Microsoft launches real-time transcription and new voice models for AI voice agentsOct 1
- Apple's smart home hub reportedly launches October 13, with a camera that never records videoOct 1
- Cloudflare releases Clef, open-weight AI models that make yes-or-no decisions fastOct 1
- GrayKey maker reportedly found a way around the iPhone's Inactivity RebootOct 1
- Fervo's Cape Station becomes the first enhanced geothermal plant to sell power commerciallyOct 1