Hackers host fake ChatGPT model on official site to spread ClickFix malware
Attackers created a custom GPT named "Plus 5.6" on chatgpt.com that redirected victims to a Google Sites page with a fake Cloudflare CAPTCHA. Pasting the suggested code installed the @input RAT, giving attackers remote control of the camera, microphone and files; Huntress handled at least 40 incidents.
- Custom GPT "Plus 5.6" mimicked an official OpenAI model on the chatgpt.com domain
- Fake Cloudflare CAPTCHA led to download of the @input remote access trojan
- Huntress responded to at least 40 incidents, dozens of users affected
- OpenAI took down the GPT on September 25, a new one appeared two days later
Read next
Security