ChatGPT Security Alert: Fake Custom GPTs Spreading Malware
Cybersecurity researchers have identified a campaign using malicious Custom GPTs to infect users with malware. Here is what to know to stay safe.
Quick facts
- Researchers at Huntress observed the campaign in late September 2026.
- At least 40 users have been infected by the malicious MSI installers.
- The attack uses a DLL sideloading chain to execute a Remote Access Trojan (RAT).
Why it matters
This incident highlights the ongoing challenge of securing AI platforms as they evolve into ecosystems hosting third-party content. While the official ChatGPT platform is legitimate, the ability for anyone to create custom models creates a new attack surface. Users should remain cautious of any unexpected prompts or file downloads originating from AI interactions.
Security researchers have warned that malicious actors are abusing the Custom GPT feature on the official ChatGPT website to distribute malware. Users searching for legitimate tools are being redirected to sites that download malicious software, according to reports from Huntress and other security outlets.
What happened?
Attackers are creating fake Custom GPTs that mimic legitimate products. When users interact with these chatbots, they are prompted to click a link hosted on Google Sites. This link leads to a "ClickFix" style attack, which triggers the download of a malicious MSI installer. Once installed, this file initiates a process known as DLL sideloading to load a Remote Access Trojan (RAT), giving attackers potential control over the victim's device.
Why is it trending?
The term chat gpt is trending in Thailand as users become aware of the risks associated with third-party tools hosted on the platform. The campaign is particularly concerning because the malicious models are hosted directly on the official ChatGPT website, making them appear trustworthy to unsuspecting users. Sponsored search results for "chatgpt" have been identified as a primary entry point for this campaign.
How to stay safe
Security experts recommend that users verify the creator of any Custom GPT before interacting with it. Avoid clicking links provided by chatbots that lead to external sites, especially if they prompt you to download and run software installers. If a site asks you to "fix" a browser or system issue by running an executable file, treat it as a high-risk threat.
Frequently asked questions
What is a Custom GPT?
A Custom GPT is a personalized version of ChatGPT that allows users to define specific instructions, upload reference files, and enable unique skills. They are created by third parties and hosted on the official ChatGPT website.
How does the malware reach users?
The attack begins when a user interacts with a malicious Custom GPT. The bot provides a link to an external site, which then attempts to trick the user into downloading and running a malicious MSI installer file.
What is a RAT?
A Remote Access Trojan (RAT) is a type of malware that allows an attacker to gain unauthorized remote control over a victim's computer. It can be used to steal data, monitor activities, or execute further malicious commands.
Are official ChatGPT models affected?
The reports focus on malicious Custom GPTs created by third parties, not the core ChatGPT models developed by OpenAI. However, because these fake models are hosted on the same platform, they can appear legitimate.
How many people have been affected?
According to Huntress, at least 40 users have been infected by the malicious campaign as of late September 2026. The total number of potential targets remains unconfirmed.
Should I stop using ChatGPT?
There is no indication that the platform itself is compromised, but users should exercise caution. Avoid downloading files from chatbots and be wary of sponsored links that claim to be official ChatGPT tools.
In this story
Sources
Last checked Oct 1, 2026 at 7:45 PM. Trends move fast, so details may change. How we work
Comments