Researchers have reported a ClickFix campaign in which malicious Custom GPTs hosted on ChatGPT were used as part of a path to remote-access malware. The reported flow redirected victims to a Google Sites page and then attempted to persuade them to run commands; Huntress said it investigated at least 40 related incidents, including two confirmed infections beginning with Custom GPTs.
The finding is a reminder that trusted AI platforms can become delivery or social-engineering surfaces even when the underlying model is not itself compromised. The immediate defensive problem is user deception: a prompt, page, or “fix” that asks a user to paste commands can bypass conventional expectations about safe AI use.
Security teams should reinforce training that software support does not require copying terminal commands from an AI chat or web page. Detection teams can also look for suspicious command execution following visits to AI-related or newly registered content, and review browser, endpoint, and identity telemetry around suspected incidents.
Organizations deploying internal AI assistants should apply content controls, reporting channels, and clear user guidance. Treat AI integrations as part of the broader phishing and endpoint-defense model rather than as a separate trust zone.
Source: Check Point Research, October 5 threat intelligence report; Huntress research.
