-
Attackers built fake ChatGPT tools to trick users into a scam called ClickFix.
-
The scam tricks people into pasting a hidden command into their own computer.
-
The hidden command installs a spy program that lets hackers control the device.

Cybersecurity researchers found a scam that uses fake ChatGPT tools to spread hidden malware. The scam tricks people into running a command that lets hackers control their computer. It shows how far attackers will go to look trustworthy online.
The firm Huntress found the attack. Hackers built fake tools called Custom GPTs. These tools looked just like real ChatGPT services, and many users had no reason to doubt them.
The fake tools lived on the real chatgpt.com website. That made the scam look far more trustworthy to regular users. Huntress found two Custom GPTs tied to this attack.
The firm also looked into more than 40 cases linked to the same scam pages. Two of those cases came straight from a Custom GPT. The other cases traced back to the wider Google Sites setup the attackers used.
A Fake ChatGPT Page Leads to a Trap
Some victims found the fake tool through a normal Google search. They searched for ChatGPT and clicked a sponsored ad near the top of the page. One fake tool used the name Plus 5.6. It looked like it came from a regular community builder, not a hacker group.
Once a person opened the tool, it showed a fake error message. The message claimed the real ChatGPT service had limited space right then. It then sent the user to a backup page hosted on Google Sites.
That backup page copied the look of a Cloudflare security check. But it did not just check if the visitor was human. Instead, it used a trick called ClickFix to push the user further into the scam.
Attackers have used similar fake Cloudflare checks in other malware campaigns, including the one reported in hackers use fake Cloudflare checks to spread psychedelic stealer in Ukraine.
ClickFix does not need a software bug to work at all. It tricks the user into doing something harmful with their own hands. In this case, the page asked users to copy a PowerShell command.
Once pasted, that command downloaded a hidden script quietly in the background. The script then installed a fake software package onto the computer.
One Click Opens the Door to Hidden Malware
After the ClickFix step, the attack grew far more complex. According to Huntress, the first version of the attack used a real Canon program. Hackers signed it properly, so it looked completely safe to use.
The hackers used that real program to load a harmful file sitting next to it. This trick is called DLL sideloading, and it hides bad code inside trusted software.
The malware also set up ways to stay on the computer long term. It used a Windows registry entry and a scheduled task. Huntress found both named Canon Configuration Reader on infected machines.
The attackers hid the real payload using even more tricks. In the first version, they hid harmful code inside a WAV audio file. The file later unpacked from a locked, encrypted folder on the drive.
The final result was a remote access trojan, known for short as a RAT. This program lets hackers view and control an infected computer from far away. It also lets hackers send the machine new commands over time and pull files or data from it whenever they choose.
The attackers later changed part of their plan. Instead of the Canon program, they used a Stardock program and a modified Stardock file. According to SecurityWeek, the final hidden malware stayed the same either way, no matter which program carried it in.
OpenAI Pulls the Tool, but a New One Shows Up
Huntress reported the first fake tool to OpenAI right away. OpenAI removed that tool on September 25. But researchers found a second fake tool just two days later, tied to the same scam.
Help Net Security later reported that the second tool was still online. However, it no longer led users to the harmful ClickFix page at that time. That does not mean the danger has fully passed for other users.
This scam shows how hackers now use trusted names to trick regular users. They mix a well-known brand with a fake safety prompt. That combination can make harmful steps feel completely normal to someone in a hurry.
Security experts keep warning users about one simple rule. Never paste a command into PowerShell, Terminal, or the Run box. This applies even if a page calls it a security check or a quick fix. A real verification step never asks anyone to paste hidden commands.
Users should also slow down before trusting any tool linked from a search ad. Sponsored results can be bought by anyone, including hackers. Checking a tool’s creator and reviews first can help avoid this trap.
The full details of this attack came from a report by an ITSecurity expert, which outlined the eight-stage chain hackers used. Each stage added another layer to hide the true goal of the scam. Staying alert to strange prompts remains the strongest defense against this kind of scam.