Hackers Abuse ChatGPT Custom GPTs to Install Dangerous Virus on Victims’ Computers
Security experts over at Huntress have recently observed a new hack that abuses ChatGPT’s custom GPT feature and ClickFix attack methods.
What starts as a basic Google search can end with victims unknowingly installing a dangerous virus, a remote access trojan (RAT), that gives attackers control of an infected device.
In this post, we break down how this attack works, why it’s so dangerous, and how you can keep your business safe.
What are Custom GPTs?
To fully understand this attack, you need to know what a custom GPT is.
In short, it’s a customized version of ChatGPT. OpenAI lets its users design and personalize their own version of ChatGPT, giving it the ability to execute unique tasks, including personal workflows or specialized business functions.
They’re hosted legitimately on OpenAI’s domain and can look very similar to your normal ChatGPT interface.
While not inherently dangerous – in fact, the right custom GPT for the right job can be a great tool – bad actors can abuse legitimate custom GPTs for malicious purposes, like having their GPT recommend links that direct users to malicious websites.
And that’s exactly what’s happening in this latest attack.
Combining Custom GPTs and ClickFix Attacks
It starts with a Google search.
Say you’re on a time crunch and need ChatGPT to help you get through some work. You go ahead and Google “ChatGPT,” and click the top link without noticing that it’s actually a sponsored ad – a paid placement from an advertiser, rather than a normal Google result.
You’re brought to what appears to be ChatGPT but is notably named: Plus 5.6.
Without realizing it, the Google link has directed you to a custom GPT. That name – “Plus 5.6” – isn’t a legitimate version of ChatGPT at all.
But without recognizing this as a warning sign, you enter your first prompt. The response isn’t quite what you’d expect:
Instead of answering your prompt normally, the bad actor’s custom GPT responds with a “Service Availability Notice” that looks something like this:
“ChatGPT is experiencing limited availability on the primary domain. We recommend using this backup domain instead.”
What follows is a link that directs you to this apparent “backup domain.”
When you click that link, you’re met with a Cloudflare CAPTCHA that has you run a script for “validation purposes.”
Before you realize it, you’ve fallen for what’s called a ClickFix attack, and that script has led to the installation of a dangerous virus.
Once installed, the virus can support the following features:
- Remote desktop control and screen broadcasts
- Capturing camera, microphone, and system audio
- Searching files and other contents on the system
- Executing additional payloads and scripts
Why Is This Attack So Dangerous?
This attack preys on people’s comfort with their AI tools.<//p>
Most people wouldn’t think twice about opening up ChatGPT, and even those who do spot the “Plus 5.6” title beneath OpenAI’s logo may think it’s just some “new version.” When you combine this trick with the CAPTCHA ClickFix attack, it can be easy to see how someone can understandably fall victim. Especially if they’re in a rush.
And if your business doesn’t have a proper AI usage policy, you may never realize your employee was using AI in the first place, making the infection source even harder to track down.
How Can I Avoid These Types of Attacks?
It comes down to two major things: awareness and oversight. You won’t be able to protect your employees if you don’t know what tools they’re using, and your employees won’t know what to look out for if they aren’t given the proper training.
Here are a few ways you can stay safe:
Never Enter Codes From a CAPTCHA
As a rule of thumb: a real verification CAPTCHA will never have you enter a code into your device. It will only require you to click a checkbox, identify images, or solve a quick puzzle. Anything that steps beyond these basic verification steps should trigger an immediate red flag.
And if you are ever unsure about a CAPTCHA, don’t hesitate to reach out to your IT department. They will be able to tell you whether the CAPTCHA is legitimate or not.
Create a Detailed AI Policy
Creating an AI usage policy means knowing what tools your employees are using, which means having a better idea of what needs to be protected.
Beyond that, an effective AI policy can also clearly identify what kind of data can be typed into an AI (marketing copy, or basic email drafts) versus what should never be uploaded (source code, customer information, financials).
That way, you’ll have much more control of how AI is used across your company, and if a security breach ever occurs due to one of these tools, it’ll be far easier to track it down.
Provide Your Team with Cyber Awareness and AI Training
Training is key to the defense of your business. By offering your team regular cyber awareness training, you can drastically reduce the chance that someone on your team will be tricked by these types of attacks.
In the case of this attack, two important things to teach your team would be:
Domain Sub-paths vs Main Domains: Just because the main domain (chatgpt.com) is safe, specific user-created “Custom GPTs” inside that domain can still direct users with malicious instructions or phishing text.
Sponsored Search Traps: Teach your team to avoid “Sponsored” search results at the top of Google or Bing. While they aren’t inherently dangerous, bad actors can use paid search ads to promote malicious or impersonating websites designed to trick users into clicking them.
Get Professional Protection Today
Hackers are turning trusted platforms against us. The key is knowing the threats and how to deal with them – and having an expert partner to guide you is critical.
That’s where The 20 MSP comes in. For a predictable, flat-rate monthly fee, we provide our clients with 24/7/365 threat monitoring, a live service helpdesk, customized cyber awareness training, and current threat intelligence.
If you’re looking for expert protection for your business, let’s talk.
About The 20 MSP
As a leading provider of managed IT services, The 20 MSP serves thousands of businesses nationwide, providing each one with white-glove service, secure and streamlined IT infrastructure, and 24/7/365 support. We believe in building lasting relationships with clients founded on trust, communication, and the delivery of high-value services for a fair and predictable price. Our clients’ success is our success, and we are committed to helping each and every organization we serve leverage technology to secure a competitive advantage and achieve new growth.

