Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Malicious ChatGPT GPTs led users to a remote access trojan

Published 30 September 2026

Malicious ChatGPT Custom GPTs directed users to a fake CAPTCHA and a command-based malware lure that installed a remote access trojan, according to Huntress. The cybersecurity firm said it responded to at least 40 incidents tied to a Google Sites domain used in the campaign, but confirmed that only two began through a malicious Custom GPT. The broader incident count does not represent 40 infections through the GPT feature. The attackers created a GPT named Plus 5.6 that appeared to offer a legitimate ChatGPT service. Some users reportedly reached it through sponsored Google search results. When opened, the GPT displayed a false notice that the service was limited on the primary domain and directed users to a backup page hosted on Google Sites. That page imitated a Cloudflare CAPTCHA and prompted visitors to copy and run a command, a social-engineering technique known as ClickFix. Huntress said the command launched PowerShell, which retrieved an obfuscated script and silently installed a malicious Windows installer. Running the command themselves could make users less likely to recognize the activity as an attack.

Now playing
0:00 / 0:00