Hackers Host Fake ChatGPT Model on Their Official Website, But It’s Actually Just Malware
- Attackers abused custom ChatGPT bots and Google Sites to distribute ClickFix malware
- Fake troubleshooting messages tricked victims into executing malicious commands
- Campaign shows trusted AI platforms increasingly leveraged in social engineering attacks
Criminals are using custom GPTs in combination with Google services to launch a ClickFix attack on their targets and deploy dangerous malware that can control the victim’s camera and microphone, experts have warned.
Huntress security researchers recently spotted a new campaign, and as soon as it was shut down, a new one appeared within days.
Abuse legitimate services
At the heart of the scam is a ChatGPT feature called “Custom GPT.” This is a version of the AI tool that a user can configure for a specific purpose, so instead of starting each conversation with a blank AI, users can create their own, with a set of instructions, knowledge and files, and different tools and capabilities. But perhaps most importantly, they can create one with unique names, personalities, and conversation starters.
Latest videos ofTechnologyRadar
A custom GPT is hosted on ChatGPT.com, so when a user navigates to one via a link in an email or instant message, they have no reason to be suspicious since the URL begins with “chatgpt.com.”
In this case, unidentified hackers created a custom GPT that they called “Plus 5.6.” OpenAI names its models “GPT-3.5”, “GPT-5 Pro” and the like, so “Plus 5.6” definitely sounds like something OpenAI could use, especially for users who aren’t really aware of progress in the AI industry. This GPT was told to display a single message, regardless of the message. That message is “We are currently experiencing limited availability on the primary domain,” followed by instructions to navigate to a “backup domain.”
This backup domain is hosted on Google Sites. In itself, Sites is a legitimate service for people who want to create websites without needing to know how to code. In this case, it’s also likely to look legitimate, although those with an eye for detail might wonder why OpenAI would use Google when it would be perfectly capable of creating a backup domain and redirecting it automatically.
Navigating to this “backup domain” shows the attackers’ true intentions: the site displays a fake Cloudflare CAPTCHA verification, asking the visitor to copy and paste a snippet of code into the Windows Run program. This is the typical ClickFix attack: the victim is shown a fake problem and immediately shown a solution.
Implementing a RAT
The “fix” leads to the download and execution of a Remote Access Trojan (RAT) that Huntress calls “@input.” This payload gives attackers almost complete control of the infected Windows computer, showing them the victim’s screen and allowing them to operate the device remotely. They can turn on the system’s webcam, microphone, and audio to watch and listen.
They can search every file on the computer, including the contents of documents, to find valuable information, but before doing any of that, they can take stock of the machine, checking what security software is installed, what programs are running, and how the device connects to a wider network.
The malware can also download and run additional components and separate strains. In fact, in most of the cases Huntress investigated, she did exactly that: without the victims realizing it. To stay out of sight, @input contacts its operators through encrypted eavesdroppers that blend in with ordinary web traffic, the researchers said. They also added that the tool appears to be part of a well-maintained and professionally managed framework.
Huntress says the campaign affected “dozens” of users, and the company’s SOC responded to “at least 40” incidents stemming from the specific Google Sites domain involved in this attack. The researchers contacted OpenAI, which helped remove the custom GPT on September 25. However, two days later a new one emerged.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment