October 1, 2026, 11:41 am | Read time: 2 minutes
Custom GPTs are intended to make using ChatGPT easier. Now, security researchers show how cybercriminals are using the feature to distribute malware on Windows computers.
Researchers from the cybersecurity platform Huntress have discovered a campaign where attackers use so-called Custom GPTs to spread malware. These are customized versions of ChatGPT created for specific tasks and made publicly available. The perpetrators used this feature to redirect users to prepared websites.
Particularly problematic is the trust many users place in the platform. According to Huntress, the criminals even advertised their manipulated GPTs through sponsored search results on Google. Those who clicked on the ads initially landed on a legitimate ChatGPT page, giving them little reason to be suspicious.
ClickFix Attack Initiates the Actual Infection
The malware was not distributed directly through ChatGPT. Instead, the manipulated GPT redirected users to a supposed backup website. There, a fake security check appeared, prompting visitors to execute a PowerShell command on their Windows PC.
This method, known as ClickFix, relies on social engineering rather than technical vulnerabilities. Users execute the malicious command themselves, bypassing many traditional security mechanisms. According to Huntress, the command downloaded a malicious installation package and initiated a multi-stage infection chain. The attackers combined legitimate, digitally signed programs with manipulated files to execute the malware as inconspicuously as possible.
Remote Access to the Affected Computer
The installed malware is a so-called Remote Access Trojan, or RAT. Such programs give attackers extensive access to infected systems. According to Huntress’s analysis, the malware can search files, collect system information, and access audio, camera, and desktop functions.
Also of interest: Is an “intelligence explosion” of AI looming?
According to the researchers, the company investigated at least 40 incidents linked to the infrastructure used. In two confirmed cases, the infection occurred via manipulated Custom GPTs. OpenAI has already removed at least one of the affected GPTs. The incident shows that cybercriminals are increasingly using well-known AI platforms for their attacks, deliberately exploiting users’ trust.