
Somebody on your team searches Google for ChatGPT, clicks the top result, and lands in a chat that tells them the service is busy and to use a backup site. The backup site shows a verification box and asks them to paste a line of text into Windows. That is a ChatGPT custom GPT ClickFix attack, and the security firm Huntress documented one in a report on fake custom GPTs and a remote access trojan. Nothing in it needs a download the person chose or a password they typed. The whole trick is getting one person, on one busy afternoon, to paste and run a command. So, the fix is a single rule you can send to everyone today. This post gives you that rule, shows how the trick looks step by step, and lays out what to do in the first hour if someone already ran the command.
Key Takeaways
Never paste or run a command that a website, chatbot, CAPTCHA, pop-up or search result gives you. Send it to every employee today.
Huntress reports at least 40 incidents tied to the Google Sites domain in this campaign, and two confirmed infections that came through a custom GPT.
Disconnect that computer from every network, call your IT provider or a security firm, and reset passwords from a different, clean device.
Tell staff never to paste a command a website or chatbot gives them
The message can be four sentences. Send it by email, post it in your team chat, and repeat it at the next meeting.
"Never paste a command into Windows Run, PowerShell, Windows Terminal or a Mac Terminal because a website, chatbot, pop-up or verification box told you to. A real CAPTCHA never asks you to do that. If a page asks, close it and tell [name] right away. Telling us quickly is always the right move, and nobody gets in trouble for it."
The last two sentences matter as much as the rule. A person who pasted something and feels embarrassed will wait, and the wait is where the damage grows. Name a real person or number they can reach, and say out loud that reporting is welcome.
This rule works because the attack has a single point where your team decides. Microsoft describes ClickFix as a technique that "attempts to trick users into running malicious commands," commonly through the Windows Run box, Windows Terminal or PowerShell. Microsoft's advice starts with user education, then limiting who can use the Run dialog, then Defender protections. The rule above is the education step in one sentence.

The attack starts with a search for ChatGPT and ends with a pasted command
Huntress's report follows the path a victim takes. The order below is the one Huntress describes.
- A sponsored result. The person searches Google for "chatgpt" and clicks a sponsored result at the top of the page.
- A custom GPT called "Plus 5.6." The link opens a custom GPT that an attacker built. "Plus 5.6" is a name the attacker chose. It is not an official OpenAI model.
- A notice about limited availability. The GPT says the main service is limited and points the person to a "backup domain."
- A page that imitates Cloudflare. The backup domain is a Google Sites page that looks like a Cloudflare verification check.
- The paste. The page tells the person to paste a PowerShell command into Windows Terminal or another command window.
- The install. The command silently downloads and runs an installer named `ISOSimple.msi`. From there, a chain of Windows steps ends with a remote access trojan, a program that lets someone else control the computer.
The last step is worth a plain description, because it explains why one paste is serious. Huntress says the installer places a legitimate, Canon-signed program on the machine, which loads a malicious file alongside it. That sets up a Run key and a scheduled task named "Canon Configuration Reader" so the program starts again later. A loader hidden inside an audio file then unpacks an encrypted archive holding the final trojan. A later wave used a Stardock-signed program and Microsoft NuGet packaging instead. Huntress's analysis describes this as a Windows infection chain.
| Stage | What the person sees | What is really happening |
|---|---|---|
| Sponsored result | A top Google result for "chatgpt" | An ad an attacker paid for |
| Custom GPT | A chat named "Plus 5.6" | A GPT the attacker built, not an official model |
| Backup domain | A Cloudflare-style check on a Google Sites page | A fake verification page |
| Paste and run | A line of text to paste into Terminal | A PowerShell command that installs a program |
| After the paste | Usually nothing obvious | A remote access trojan set to restart with the computer |
Huntress states its numbers this way: its security operations team has responded to at least 40 incidents tied to the specific Google Sites domain in this campaign, and two of those incidents were confirmed to have come through a custom GPT. Those are Huntress's figures for its own response work, and they are the only counts to quote. Huntress also said its own assessment is that "Threat actors are finding success in this specific abuse of Custom GPTs for social engineering and are continuing to rely on this technique."
Huntress reports contacting OpenAI about the first custom GPT, which was removed by September 25, 2026. On September 27, Huntress found a second, related GPT. A GPT that looks like a trap can be reported through the route OpenAI documents, covered below.

A chatgpt.com page is not proof that a GPT is safe
Staff who use ChatGPT daily sometimes assume that anything hosted on chatgpt.com is trustworthy. The Huntress case shows why that habit needs a small adjustment. A custom GPT is built by whoever made it. OpenAI's page on GPTs explains that a GPT can carry its own instructions, knowledge files, capabilities, apps and actions, and it advises using only connected services you trust. The chat window can look familiar even when the person who wrote the instructions is a stranger.
Three habits help, and none of them requires blocking anything:
- Open ChatGPT by typing the address yourself or using a bookmark, instead of clicking a sponsored search result.
- Treat any GPT that sends you to another website for verification, a download or an upgrade as a stop sign.
- Treat any request to copy and run a command as the same stop sign, wherever it appears, including on a real page.
You do not need to ban ChatGPT. The same ClickFix method shows up through search ads, phishing emails, compromised websites and fake support pages, so blocking one site leaves the trick itself untouched. The control that covers all of those is the rule from the top of this post.
If a staff member finds a GPT that looks like a trap, they can report it. OpenAI's help page on reporting content in ChatGPT says to open the GPT, click its name, choose Report GPT, and follow the prompts. There is also an OpenAI content report form. Reporting helps the next person, and it does not replace telling your own IT contact.
If someone already pasted the command, start with the first hour
Treat the computer as compromised even if the screen looks normal. A remote access trojan does not announce itself, so waiting for symptoms is the wrong test. These steps follow Microsoft's incident response guidance and Huntress's report, in the order that matters.
- Disconnect the computer. Turn off Wi-Fi, unplug Ethernet, disconnect any VPN and shared drives. If your business uses a security product with a device isolation feature, your IT contact can use it. Microsoft documents device isolation in Defender for businesses that have it.
- Stop using that computer. No email, banking or admin work on it, and no more experiments with the command.
- Write down what happened. Record the time, the web address, the command as it appeared on screen if it is still visible, the computer name, the username and any security alerts.
- Call your IT provider. If you do not have one, call a managed security provider, your cyber-insurance incident line or an incident-response firm.
- Reset passwords from a different, clean device. Start with the affected user, then administrators, email, VPN, cloud storage and finance accounts. Revoke active sessions and review multi-factor authentication settings, since a stolen session can outlast a password change.
Reset the passwords from a clean device because anything typed on the affected computer could be seen by whoever controls it. This is the step people skip, and it is the one that protects your email and bank logins.

The person who examines the computer will look for specific traces from this campaign. Give them what Huntress named:
| Item | What it is |
|---|---|
| `ISOSimple.msi` | The installer the pasted command downloads |
| `COTFileReadApp.exe` | The Canon-signed program that loads the malicious file |
| "Canon Configuration Reader" | The name of the scheduled task and Run key entry |
| Audio file with a hidden loader | Unpacks the encrypted archive with the trojan |
| NuGet packages and a Stardock-signed program | Used in a later wave of the campaign |
| `Trojan:Script/Wacatac.H!ml` | A Microsoft Defender detection name to look for |
A signed program is not a safe program. Huntress describes attackers loading their own code through a legitimate signed Canon application, so a valid signature on a file does not clear it. Do not let anyone in your office decide the computer is clean because an antivirus scan quarantined something. Have someone with the tools confirm it.
Ten minutes of checks show where your business stands
You can do these before lunch. They cost nothing, and they tell you how much a single paste could reach.
- Ask whether each person is a standard user or a local administrator. Write down the exceptions. Administrator rights give a malicious program more access, so fewer administrators means less exposure.
- Open your security settings on each computer. Confirm that real-time protection and cloud protection are on and that updates are recent. Microsoft's Defender for Endpoint documentation shows what those settings look like.
- List every computer that touches business data. Include laptops used at home, temporary devices, Macs and contractors' machines. ClickFix also has Terminal versions for macOS and Linux, so the rule and the checks apply beyond Windows.
- Name who staff call. One person or one number, written where everyone can find it.
- Confirm multi-factor authentication is on for email, cloud storage and finance accounts, so a stolen password alone does not open them.
If a command was already run, stop this list and isolate that computer first.
Some jobs take longer than ten minutes. These are rough sizes to plan around, and they vary with how many computers you have:
| Fix | Rough size of the job |
|---|---|
| Send the one-rule message and run a short example briefing | 30 to 60 minutes |
| Name a contact, a provider and an escalation path | 1 to 2 hours |
| Reset passwords and revoke sessions for one user | 1 to 4 hours |
| Turn on and verify endpoint protection on a small, standard set of computers | About a day |
| Remove local administrator rights and test business software | 1 to 3 days, longer if older programs break |
| Restrict PowerShell with application control | Several days to several weeks, because legitimate automation has to keep working |
That last row is the deeper control. Microsoft's PowerShell application control documentation recommends App Control for Business and Constrained Language Mode rather than relying only on PowerShell's execution policy. It is worth doing for a business that can support it, and it is a later project, not this week's job.

Paid help makes sense in a few situations, and the free steps come first
Everything in the sections above is free or already included in tools you likely own: the rule, standard accounts, updates, Microsoft Defender if you use Windows, multi-factor authentication, a device list and a named contact. A staff member reading a headline about a fake GPT does not, on its own, call for a paid engagement.
Outside help earns its cost in these cases:
- A command was run, and you need someone to examine the computer and confirm what was contained.
- You cannot tell which computers have protection turned on.
- Accounts may be exposed and you cannot review sign-in activity yourself.
- You hold regulated or sensitive customer data.
- You want written evidence that the incident was contained.
What the help covers matters. Examining a possibly infected computer is work for an IT provider, a managed security provider or an incident-response firm. A website security audit looks at the controls around your business, such as accounts, access, updates and how quickly you would notice a problem, and it can tell you whether you need a specialist for the rest. Ask any provider to say exactly which of those they are doing.
Would your team handle a ClickFix prompt?
Pick an answer to begin.
1. A verification page tells an employee to press Win + R, paste a line of text and press Enter. What should they do?
2. Huntress reported at least 40 incidents tied to the Google Sites domain. How many of them did it confirm came through a custom GPT?
3. An employee pasted the command an hour ago and the computer seems fine. What is the right next step?
Frequently Asked Questions About chatgpt custom gpt clickfix
Can a custom GPT install malware by itself?
No. In the campaign Huntress documented, the GPT sent people to a fake page, and the infection needed the person to paste and run a command. The rule about never pasting a command breaks that chain at its only human step.
Is ChatGPT Plus 5.6 a real model?
No. Huntress identified "Plus 5.6" as the name of a custom GPT the attackers built. It is not an official OpenAI model.
What is ClickFix?
It is a social-engineering technique that shows a fake CAPTCHA, error or verification step and tells the person to copy a command and run it in Windows Run, PowerShell or a Terminal. CISA's advisory on the Interlock ransomware group lists it as "User Execution: Malicious Copy and Paste."
What should I do if I already ran the command?
Disconnect the computer from every network, stop using it, write down what happened, call your IT provider or a security firm, and reset passwords from a different, clean device. Do not wait for symptoms.
Should we ban ChatGPT at work?
Banning it does not address the trick, which also arrives through search ads, phishing emails and fake support pages. Give staff the one rule, keep standard user accounts and protection on every computer, and name someone to report to.
How do I report a malicious GPT?
Open the GPT, click its name, choose Report GPT and follow the prompts, or use OpenAI's content report form. Then tell your own IT contact too.
Final Thoughts
The Huntress case is a reminder that a familiar chat window can carry an unfamiliar request. Nobody on your team has to spot a fake GPT by its looks. They only have to remember that no legitimate page needs them to paste a command into their computer, and that reporting it is welcome.
Send the one-rule message today, run the ten-minute check this week, and write down who staff should call. If a command was already run, treat that computer as compromised, disconnect it, and reset passwords from a clean device before anything else.
If you would like a second set of eyes on the controls around your business, Web Leveling can review accounts, access and updates through our website security audit, and tell you whether an incident-response specialist is the right next call. Send us a note through the contact page and tell us what you are seeing. We work with small and medium businesses across the country and overseas.
Terms
ClickFix words in this post
Tap a term to see what it means.
ClickFix. A trick that shows a fake CAPTCHA or error and tells the person to paste and run a command.
Custom GPT. A version of ChatGPT that someone builds with their own instructions, files and connected tools.
PowerShell. A Windows tool that runs typed commands, which attackers ask victims to paste into it.
Remote access trojan. A program that lets someone else control a computer from a distance.
Endpoint protection. Security software on each computer that watches for and blocks malicious activity.
Standard user. An account that cannot install software or change system settings without an administrator.
Device isolation. Cutting a computer off from the network so a problem cannot spread while it is examined.




