Security researchers have identified a new abuse pattern targeting ChatGPT’s Custom GPTs feature, where attackers build fake product-branded chatbots to lure victims toward malware delivery sites. The campaign, observed by Huntress in late September 2026, is the latest instance of threat actors weaponizing legitimate AI platform features to bypass user suspicion.

According to Dark Reading and The Hacker News, the attackers create Custom GPTs that impersonate legitimate products and services. Victims interacting with these GPTs are redirected to external sites hosted on, or abusing the trust of, legitimate domains belonging to OpenAI and Google. Because these domains are widely trusted and often whitelisted by security tools, the redirection chain is less likely to trigger alerts.

ClickFix Tactics Deliver the Payload

The final stage of the attack relies on ClickFix-style social engineering, a technique that has become increasingly common in 2026 campaigns. ClickFix lures typically present victims with a fake error message or verification prompt instructing them to manually copy and run a command, often via the Windows Run dialog or terminal. This sidesteps many automated malware detection mechanisms because the malicious code is executed directly by the user rather than through a file download or exploit.

In this campaign, the ClickFix pages ultimately deliver a remote access trojan (RAT), giving attackers persistent control over compromised machines. Huntress noted this represents another example of a trusted AI platform feature being repurposed for malware distribution, following earlier abuse of other shared or embeddable AI functionality.

Why This Matters

The use of Custom GPTs as a lure mechanism reflects a broader trend of attackers exploiting legitimate AI tooling to add credibility to phishing and malware campaigns. Because the initial point of contact is a seemingly official ChatGPT interface, users may be more inclined to trust subsequent instructions, including ClickFix prompts that would otherwise raise red flags.

Security teams should treat unsolicited instructions to manually execute commands, regardless of the source platform, as a strong indicator of compromise. Organizations are advised to monitor for unusual outbound connections following ChatGPT or Google domain interactions and to reinforce user awareness around ClickFix-style social engineering, which continues to appear across multiple malware delivery campaigns.