Cybersecurity briefing
/
feb 16, 2025
A Custom GPT Became the First Step in a ClickFix Malware Chain
A malicious custom GPT on ChatGPT launched a ClickFix-style malware chain. See how Huntress traced it and how Nebulock aids the investigation.
/
AUTHOR

Jeff Dyer

Overview
A custom GPT on the real ChatGPT website became an entry point for a malware campaign reported on September 29. Victims were led from a sponsored search result to a counterfeit security check, then instructed to run a command that installed a remote access trojan. The case shows why a trusted website, a signed application, and a familiar looking verification prompt cannot each be treated as proof that the workflow is safe.
A legitimate host carried an attacker controlled conversation
Huntress researchers found two attacker created custom GPTs titled “Plus 5.6.” A custom GPT is a user configured experience hosted by OpenAI, not a new official model. In the cases Huntress examined, some users searching for ChatGPT clicked a sponsored Google result that opened one of these GPT pages on the legitimate chatgpt.com domain. The page identified a community builder, but its title could still be mistaken for an official version by a hurried user.
When a visitor interacted with the custom GPT, it returned a service availability notice and directed the visitor to a supposed backup site. That destination was a Google Sites page styled as a Cloudflare verification check. Its instruction to copy and run a PowerShell command was the decisive step. A website can ask a person to do that, but an ordinary browser verification does not require a user to paste a command into a local shell.
Huntress says its security operations center responded to at least 40 incidents tied to the Google Sites domain. It confirmed two of those incidents came through a custom GPT. The larger incident count should not be described as 40 custom GPT infections, because the researchers did not establish that route for every case. OpenAI removed the first GPT by September 25; Huntress found a second one linked to the campaign on September 27.
From pasted command to persistent access
The pasted command fetched and ran an obfuscated PowerShell script. That script downloaded an MSI package, installed it silently, and deleted itself. The package launched a legitimately signed Canon application from an unusual user profile location. A modified library placed alongside that application loaded the next malicious stage through DLL sideloading. Huntress later found a variant that used a signed Stardock application and a different carrier file, while retaining the same underlying remote access payload.
This chain is a useful reminder that a valid signature authenticates a particular file, not every file or behavior around it. The signed application was real. The nearby library, installer, launch context, and persistence were the suspicious parts. According to Huntress’s technical analysis, the malware established both a user Run key and a scheduled task, then used a custom encrypted file system to hide the final payload. The resulting trojan had remote desktop, file search, host reconnaissance, and follow on payload capabilities.
The researchers observed anti-analysis techniques as well, including an attempted AMSI bypass and code that sought to avoid some endpoint hooks. Those details help explain why a defender should follow the process sequence rather than depend on a single file hash or the reputation of the first website. A new custom GPT, Google Sites page, installer name, or signed host could change while the same malicious workflow persists.

The investigation should follow behavior across systems
Start with the event that turns a web lure into local execution: a user launched PowerShell, which invoked msiexec on an MSI in the temporary directory. Then inspect the installed application’s path, the DLLs loaded from that directory, and any Run key or scheduled task created soon afterward. Huntress published specific indicators, including the persistence names “Canon Configuration Reader” and “Stardock DeElevation Tool,” but it also cautioned that future variants may use different signed applications. Behavioral relationships age better than a fixed list of names.
This is a practical threat hunting problem when the first clue is a user report, a suspicious ad, or an endpoint alert with incomplete context. Nebulock describes its platform as a way to surface and investigate endpoint and identity based threats using connected telemetry. In an environment where the relevant endpoint records are available, that kind of hunting can help analysts look for related process chains and persistence across other machines. It does not remove a malicious custom GPT, block a pasted command, or replace the endpoint controls and investigation needed to confirm compromise.
For a confirmed affected host, responders should preserve evidence, isolate the endpoint as appropriate, examine the user’s account activity, and determine whether the trojan accessed sensitive data or other systems. Removing only one scheduled task is inadequate if a running implant recreates it. Huntress observed that the persistence mechanisms can be restored while the malware remains active, so cleanup must account for the process and both persistence paths.

Reduce trust in the path, not just the domain
Security teams can make this attack harder at several points. Teach users to treat a custom GPT by a community builder differently from an official service announcement, and to report any “verification” page that asks for shell commands. Restrict unapproved script and installer execution where operationally feasible. Monitor sponsored result and collaboration platform abuse, but do not assume that domain allowlists will identify attacker controlled content hosted by legitimate services.
On endpoints, retain process creation, installer, module load, and persistence telemetry long enough to reconstruct the sequence. Test detections against PowerShell launching a silent MSI from a temporary path, a signed application starting from an unexpected user profile folder, and a Run key paired with a scheduled task. Review exceptions carefully so legitimate administration remains possible without making the signal meaningless.
The broader lesson is that this campaign borrowed trust at each hop: a sponsored result, a real AI platform, a familiar verification design, and signed software. None of those individually established that the requested action was authorized. Organizations should verify the source of instructions, constrain local execution, and investigate the full chain when a suspicious command has been run.
/
BLOG
Other insights

Cybersecurity briefing
/
Sep 29, 2026
A Simulated AI Supply Chain Attack Exposes a Real Testing Gap

Cybersecurity briefing
/
Sep 29, 2026
AI Agents Need Security Boundaries They Cannot Talk Their Way Around

Cybersecurity briefing
/
Sep 15, 2026