website security

Fake ChatGPT Custom GPT ClickFix scam: the one rule for staff

Huntress found fake ChatGPT custom GPTs used in a ClickFix attack. Get the one rule to tell staff and the first steps if someone pasted the command.

Somebody on your team searches Google for ChatGPT, clicks the top result, and lands in a chat that tells them the service is busy and to use a backup site. The backup site shows a verification box and asks them to paste a line of text into Windows. That is a ChatGPT custom GPT ClickFix attack, and the security firm Huntress documented one in a report on fake custom GPTs and a remote access trojan. Nothing in it needs a download the person chose or a password they typed. The whole trick is getting one person, on one busy afternoon, to paste and run a command. So, the fix is a single rule you can send to everyone today. This post gives you that rule, shows how the trick looks step by step, and lays out what to do in the first hour if someone already ran the command.

Key Takeaways

The one rule

Never paste or run a command that a website, chatbot, CAPTCHA, pop-up or search result gives you. Send it to every employee today.

Huntress's numbers

Huntress reports at least 40 incidents tied to the Google Sites domain in this campaign, and two confirmed infections that came through a custom GPT.

If it was run

Disconnect that computer from every network, call your IT provider or a security firm, and reset passwords from a different, clean device.

Tell staff never to paste a command a website or chatbot gives them

The message can be four sentences. Send it by email, post it in your team chat, and repeat it at the next meeting.

"Never paste a command into Windows Run, PowerShell, Windows Terminal or a Mac Terminal because a website, chatbot, pop-up or verification box told you to. A real CAPTCHA never asks you to do that. If a page asks, close it and tell [name] right away. Telling us quickly is always the right move, and nobody gets in trouble for it."

The last two sentences matter as much as the rule. A person who pasted something and feels embarrassed will wait, and the wait is where the damage grows. Name a real person or number they can reach, and say out loud that reporting is welcome.

This rule works because the attack has a single point where your team decides. Microsoft describes ClickFix as a technique that "attempts to trick users into running malicious commands," commonly through the Windows Run box, Windows Terminal or PowerShell. Microsoft's advice starts with user education, then limiting who can use the Run dialog, then Defender protections. The rule above is the education step in one sentence.

A closed laptop on a wooden desk beside a small pad of blank sticky notes and a pen.
A rule short enough to fit on a sticky note is short enough to remember on a busy day.

The attack starts with a search for ChatGPT and ends with a pasted command

Huntress's report follows the path a victim takes. The order below is the one Huntress describes.

  1. A sponsored result. The person searches Google for "chatgpt" and clicks a sponsored result at the top of the page.
  2. A custom GPT called "Plus 5.6." The link opens a custom GPT that an attacker built. "Plus 5.6" is a name the attacker chose. It is not an official OpenAI model.
  3. A notice about limited availability. The GPT says the main service is limited and points the person to a "backup domain."
  4. A page that imitates Cloudflare. The backup domain is a Google Sites page that looks like a Cloudflare verification check.
  5. The paste. The page tells the person to paste a PowerShell command into Windows Terminal or another command window.
  6. The install. The command silently downloads and runs an installer named `ISOSimple.msi`. From there, a chain of Windows steps ends with a remote access trojan, a program that lets someone else control the computer.

The last step is worth a plain description, because it explains why one paste is serious. Huntress says the installer places a legitimate, Canon-signed program on the machine, which loads a malicious file alongside it. That sets up a Run key and a scheduled task named "Canon Configuration Reader" so the program starts again later. A loader hidden inside an audio file then unpacks an encrypted archive holding the final trojan. A later wave used a Stardock-signed program and Microsoft NuGet packaging instead. Huntress's analysis describes this as a Windows infection chain.

The Huntress campaign at a glance
StageWhat the person seesWhat is really happening
Sponsored resultA top Google result for "chatgpt"An ad an attacker paid for
Custom GPTA chat named "Plus 5.6"A GPT the attacker built, not an official model
Backup domainA Cloudflare-style check on a Google Sites pageA fake verification page
Paste and runA line of text to paste into TerminalA PowerShell command that installs a program
After the pasteUsually nothing obviousA remote access trojan set to restart with the computer
StageSponsored result
What the person seesA top Google result for "chatgpt"
What is really happeningAn ad an attacker paid for
StageCustom GPT
What the person seesA chat named "Plus 5.6"
What is really happeningA GPT the attacker built, not an official model
StageBackup domain
What the person seesA Cloudflare-style check on a Google Sites page
What is really happeningA fake verification page
StagePaste and run
What the person seesA line of text to paste into Terminal
What is really happeningA PowerShell command that installs a program
StageAfter the paste
What the person seesUsually nothing obvious
What is really happeningA remote access trojan set to restart with the computer

Huntress states its numbers this way: its security operations team has responded to at least 40 incidents tied to the specific Google Sites domain in this campaign, and two of those incidents were confirmed to have come through a custom GPT. Those are Huntress's figures for its own response work, and they are the only counts to quote. Huntress also said its own assessment is that "Threat actors are finding success in this specific abuse of Custom GPTs for social engineering and are continuing to rely on this technique."

Huntress reports contacting OpenAI about the first custom GPT, which was removed by September 25, 2026. On September 27, Huntress found a second, related GPT. A GPT that looks like a trap can be reported through the route OpenAI documents, covered below.

A small stack of unopened envelopes beside a switched-off desktop monitor on a tidy office desk.
The path from a search to a pasted command takes a minute, and nothing on screen looks alarming along the way.

A chatgpt.com page is not proof that a GPT is safe

Staff who use ChatGPT daily sometimes assume that anything hosted on chatgpt.com is trustworthy. The Huntress case shows why that habit needs a small adjustment. A custom GPT is built by whoever made it. OpenAI's page on GPTs explains that a GPT can carry its own instructions, knowledge files, capabilities, apps and actions, and it advises using only connected services you trust. The chat window can look familiar even when the person who wrote the instructions is a stranger.

Three habits help, and none of them requires blocking anything:

  • Open ChatGPT by typing the address yourself or using a bookmark, instead of clicking a sponsored search result.
  • Treat any GPT that sends you to another website for verification, a download or an upgrade as a stop sign.
  • Treat any request to copy and run a command as the same stop sign, wherever it appears, including on a real page.

You do not need to ban ChatGPT. The same ClickFix method shows up through search ads, phishing emails, compromised websites and fake support pages, so blocking one site leaves the trick itself untouched. The control that covers all of those is the rule from the top of this post.

If a staff member finds a GPT that looks like a trap, they can report it. OpenAI's help page on reporting content in ChatGPT says to open the GPT, click its name, choose Report GPT, and follow the prompts. There is also an OpenAI content report form. Reporting helps the next person, and it does not replace telling your own IT contact.

If someone already pasted the command, start with the first hour

Treat the computer as compromised even if the screen looks normal. A remote access trojan does not announce itself, so waiting for symptoms is the wrong test. These steps follow Microsoft's incident response guidance and Huntress's report, in the order that matters.

  1. Disconnect the computer. Turn off Wi-Fi, unplug Ethernet, disconnect any VPN and shared drives. If your business uses a security product with a device isolation feature, your IT contact can use it. Microsoft documents device isolation in Defender for businesses that have it.
  2. Stop using that computer. No email, banking or admin work on it, and no more experiments with the command.
  3. Write down what happened. Record the time, the web address, the command as it appeared on screen if it is still visible, the computer name, the username and any security alerts.
  4. Call your IT provider. If you do not have one, call a managed security provider, your cyber-insurance incident line or an incident-response firm.
  5. Reset passwords from a different, clean device. Start with the affected user, then administrators, email, VPN, cloud storage and finance accounts. Revoke active sessions and review multi-factor authentication settings, since a stolen session can outlast a password change.

Reset the passwords from a clean device because anything typed on the affected computer could be seen by whoever controls it. This is the step people skip, and it is the one that protects your email and bank logins.

A single office key on a small ring resting beside a closed padlock on a plain table.
Cutting a computer off from the network and changing passwords elsewhere comes before any cleanup.

The person who examines the computer will look for specific traces from this campaign. Give them what Huntress named:

What to hand your IT contact from the Huntress report
ItemWhat it is
`ISOSimple.msi`The installer the pasted command downloads
`COTFileReadApp.exe`The Canon-signed program that loads the malicious file
"Canon Configuration Reader"The name of the scheduled task and Run key entry
Audio file with a hidden loaderUnpacks the encrypted archive with the trojan
NuGet packages and a Stardock-signed programUsed in a later wave of the campaign
`Trojan:Script/Wacatac.H!ml`A Microsoft Defender detection name to look for
Item`ISOSimple.msi`
What it isThe installer the pasted command downloads
Item`COTFileReadApp.exe`
What it isThe Canon-signed program that loads the malicious file
Item"Canon Configuration Reader"
What it isThe name of the scheduled task and Run key entry
ItemAudio file with a hidden loader
What it isUnpacks the encrypted archive with the trojan
ItemNuGet packages and a Stardock-signed program
What it isUsed in a later wave of the campaign
Item`Trojan:Script/Wacatac.H!ml`
What it isA Microsoft Defender detection name to look for

A signed program is not a safe program. Huntress describes attackers loading their own code through a legitimate signed Canon application, so a valid signature on a file does not clear it. Do not let anyone in your office decide the computer is clean because an antivirus scan quarantined something. Have someone with the tools confirm it.

Ten minutes of checks show where your business stands

You can do these before lunch. They cost nothing, and they tell you how much a single paste could reach.

  1. Ask whether each person is a standard user or a local administrator. Write down the exceptions. Administrator rights give a malicious program more access, so fewer administrators means less exposure.
  2. Open your security settings on each computer. Confirm that real-time protection and cloud protection are on and that updates are recent. Microsoft's Defender for Endpoint documentation shows what those settings look like.
  3. List every computer that touches business data. Include laptops used at home, temporary devices, Macs and contractors' machines. ClickFix also has Terminal versions for macOS and Linux, so the rule and the checks apply beyond Windows.
  4. Name who staff call. One person or one number, written where everyone can find it.
  5. Confirm multi-factor authentication is on for email, cloud storage and finance accounts, so a stolen password alone does not open them.

If a command was already run, stop this list and isolate that computer first.

Some jobs take longer than ten minutes. These are rough sizes to plan around, and they vary with how many computers you have:

Rough size of each fix
FixRough size of the job
Send the one-rule message and run a short example briefing30 to 60 minutes
Name a contact, a provider and an escalation path1 to 2 hours
Reset passwords and revoke sessions for one user1 to 4 hours
Turn on and verify endpoint protection on a small, standard set of computersAbout a day
Remove local administrator rights and test business software1 to 3 days, longer if older programs break
Restrict PowerShell with application controlSeveral days to several weeks, because legitimate automation has to keep working
FixSend the one-rule message and run a short example briefing
Rough size of the job30 to 60 minutes
FixName a contact, a provider and an escalation path
Rough size of the job1 to 2 hours
FixReset passwords and revoke sessions for one user
Rough size of the job1 to 4 hours
FixTurn on and verify endpoint protection on a small, standard set of computers
Rough size of the jobAbout a day
FixRemove local administrator rights and test business software
Rough size of the job1 to 3 days, longer if older programs break
FixRestrict PowerShell with application control
Rough size of the jobSeveral days to several weeks, because legitimate automation has to keep working

That last row is the deeper control. Microsoft's PowerShell application control documentation recommends App Control for Business and Constrained Language Mode rather than relying only on PowerShell's execution policy. It is worth doing for a business that can support it, and it is a later project, not this week's job.

A ring binder labeled with blank tape on a shelf, next to a small stack of paper folders.
A written list of computers and who uses them lets you find the affected device in minutes.

Everything in the sections above is free or already included in tools you likely own: the rule, standard accounts, updates, Microsoft Defender if you use Windows, multi-factor authentication, a device list and a named contact. A staff member reading a headline about a fake GPT does not, on its own, call for a paid engagement.

Outside help earns its cost in these cases:

  • A command was run, and you need someone to examine the computer and confirm what was contained.
  • You cannot tell which computers have protection turned on.
  • Accounts may be exposed and you cannot review sign-in activity yourself.
  • You hold regulated or sensitive customer data.
  • You want written evidence that the incident was contained.

What the help covers matters. Examining a possibly infected computer is work for an IT provider, a managed security provider or an incident-response firm. A website security audit looks at the controls around your business, such as accounts, access, updates and how quickly you would notice a problem, and it can tell you whether you need a specialist for the rest. Ask any provider to say exactly which of those they are doing.

Would your team handle a ClickFix prompt?

Pick an answer to begin.

1. A verification page tells an employee to press Win + R, paste a line of text and press Enter. What should they do?

2. Huntress reported at least 40 incidents tied to the Google Sites domain. How many of them did it confirm came through a custom GPT?

3. An employee pasted the command an hour ago and the computer seems fine. What is the right next step?

Frequently Asked Questions About chatgpt custom gpt clickfix

Can a custom GPT install malware by itself?

No. In the campaign Huntress documented, the GPT sent people to a fake page, and the infection needed the person to paste and run a command. The rule about never pasting a command breaks that chain at its only human step.

Is ChatGPT Plus 5.6 a real model?

No. Huntress identified "Plus 5.6" as the name of a custom GPT the attackers built. It is not an official OpenAI model.

What is ClickFix?

It is a social-engineering technique that shows a fake CAPTCHA, error or verification step and tells the person to copy a command and run it in Windows Run, PowerShell or a Terminal. CISA's advisory on the Interlock ransomware group lists it as "User Execution: Malicious Copy and Paste."

What should I do if I already ran the command?

Disconnect the computer from every network, stop using it, write down what happened, call your IT provider or a security firm, and reset passwords from a different, clean device. Do not wait for symptoms.

Should we ban ChatGPT at work?

Banning it does not address the trick, which also arrives through search ads, phishing emails and fake support pages. Give staff the one rule, keep standard user accounts and protection on every computer, and name someone to report to.

How do I report a malicious GPT?

Open the GPT, click its name, choose Report GPT and follow the prompts, or use OpenAI's content report form. Then tell your own IT contact too.

Final Thoughts

The Huntress case is a reminder that a familiar chat window can carry an unfamiliar request. Nobody on your team has to spot a fake GPT by its looks. They only have to remember that no legitimate page needs them to paste a command into their computer, and that reporting it is welcome.

Send the one-rule message today, run the ten-minute check this week, and write down who staff should call. If a command was already run, treat that computer as compromised, disconnect it, and reset passwords from a clean device before anything else.

If you would like a second set of eyes on the controls around your business, Web Leveling can review accounts, access and updates through our website security audit, and tell you whether an incident-response specialist is the right next call. Send us a note through the contact page and tell us what you are seeing. We work with small and medium businesses across the country and overseas.

Terms

ClickFix words in this post

Tap a term to see what it means.

ClickFix. A trick that shows a fake CAPTCHA or error and tells the person to paste and run a command.

Custom GPT. A version of ChatGPT that someone builds with their own instructions, files and connected tools.

PowerShell. A Windows tool that runs typed commands, which attackers ask victims to paste into it.

Remote access trojan. A program that lets someone else control a computer from a distance.

Endpoint protection. Security software on each computer that watches for and blocks malicious activity.

Standard user. An account that cannot install software or change system settings without an administrator.

Device isolation. Cutting a computer off from the network so a problem cannot spread while it is examined.