Huntress published research on 28 September 2026 on a campaign that uses OpenAI's own platform as the first step of a malware delivery chain. The lure is a Custom GPT named Plus 5.6, hosted where every Custom GPT is hosted, on chatgpt.com, and people reach it through a sponsored Google result for the search term chatgpt.
Nothing in that sentence requires a vulnerability. Every component is a product feature used the way it was built.
The chain, as the victim sees it
A person searches for chatgpt. The paid result at the top of the page leads to a Custom GPT whose name reads like a subscription tier. From there they are sent to a page on Google Sites dressed as a Cloudflare check, the kind of interstitial everyone has learned to click through.
The page then does what ClickFix campaigns do: it tells the visitor to copy a line and paste it into a terminal. The line fetches a script into the temporary folder and runs it. Huntress describes the result as an eight-stage chain ending in a remote access trojan that can run remote desktop sessions, stream the screen, take camera, microphone and system audio, browse and search files, and load further payloads as executables, libraries, installers or scripts.
Huntress ties at least 40 incidents to the same Google Sites domain, of which two are confirmed as starting inside the Custom GPT.
Why the domains matter more than the malware
The malware is unremarkable. The route is the story, because every hop happens on infrastructure a security awareness programme has spent years teaching people to trust.
The search result carries Google's ad placement. The destination is openai.com's product domain, which no blocklist will touch and no proxy category will flag. The staging page is on google.com's own site hosting. By the time anything suspicious is asked of the victim, three well-known brands have vouched for the path.
And what is finally asked of them is not a download. It is a copy and paste into a terminal, which no download inspection sees and no mail gateway touches, performed by the user on their own machine.
Take-down is not removal
Huntress reported the Custom GPT to OpenAI, and it was removed on 25 September. On 27 September the researchers found a new Custom GPT from the same campaign, reusing the name.
Two days is the gap, and it is the number worth keeping. A platform that lets anyone publish an assistant under any name has to treat removal as a rate, not an event: a campaign that can republish faster than a report can be processed is not interrupted by the take-down, only inconvenienced.
Indicators published with the research include a command-and-control address written in decimal form, installer filenames built from thirty-two hex characters, and a persistence entry named to look like a printer utility.
Why the name is part of the attack
Plus 5.6 is not a random string. It reads as a tier of the product the victim was already searching for, in a store where the publisher's identity is not something a casual user checks and where names are not reserved.
That is the gap this campaign lives in. App stores for phones learned, slowly and expensively, to police names that impersonate the platform itself. A directory of user-published assistants hosted on the platform's own domain inherits none of that, and the only visible difference between an official feature and an impersonation of one is a developer field most people never read.
Why anyone pastes a command at all
ClickFix works because it is phrased as a repair, not an install.
The page says verification failed and here is the fix. The instruction arrives after a failure the visitor can see, which makes it feel like troubleshooting rather than installation, and the action requested is not one that any security training covers. People are told not to open attachments and not to enter passwords on strange pages. Almost nobody has been told that pasting a line into a terminal is how machines get taken over.
It is also the step that defeats most of the controls an organisation has bought. Nothing is downloaded by the browser, no document is opened, no macro runs. The user, who is authorised to run programs, runs one.
What to do
- Teach the specific instruction, not the general warning. The step that compromises the machine is being asked to paste a command into a terminal. No legitimate CAPTCHA has ever required that.
- Treat terminal paste as a detection. Shell launches with clipboard-shaped arguments, and script execution out of the temporary folder, are both observable.
- Do not let brand domains stand in for trust in filtering decisions. Content on chatgpt.com, sites.google.com and similar hosts is published by users.
- Check for the published indicators if you support users who search for AI tools, which now means most organisations.
What is not established
- Who is behind the campaign. Huntress names no actor.
- How many people reached the Custom GPT and did not act on it, which would say how well the lure converts.
- Whether the ad was bought with a compromised Google account or a fresh one.
- What OpenAI will do differently about republished Custom GPTs, beyond removing the ones reported.