Hackers exploit ChatGPT Custom GPTs to spread remote-access trojans via fake backup sites.

Huntress researchers say attackers used malicious ChatGPT Custom GPTs, including one called “Plus 5.6,” to lure people searching for ChatGPT through sponsored Google results to a fake backup site. The GPTs were hosted on ChatGPT’s legitimate domain, but the campaign did not require a compromise of OpenAI’s systems. The linked Google Sites page impersonated a Cloudflare verification and used a ClickFix prompt to trick visitors into running a PowerShell command, launching a multistage infection that installed a remote-access trojan. The malware could enable remote control, capture audio and video, and deliver additional malware. Huntress investigated at least 40 incidents tied to the Google Sites domain, but confirmed only two involved a Custom GPT; after the first malicious model was removed, a similar variant reportedly appeared within 48 hours.
The malicious GPT returned the same “Service Availability Notice” regardless of what a user typed, claiming limited availability on the primary domain and directing them to upgrade to Plus or use a backup site.
The infection chain used a legitimate Canon-signed application to sideload a modified DLL containing the malware. The RAT established persistence through a Windows Registry Run key and a scheduled task, both named “Canon Configuration Reader.”
Some attack variants used the decimal IP address 1614733393, which resolves to 96.62.224.81, as an obfuscation technique intended to evade casual inspection and some URL filters.
OpenAI plans to retire Custom GPTs on December 11, according to BleepingComputer.
Publishers
16
Articles
10
Reach
26