[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6xoQa6i121M0tTcyNMI8TIcWPDW3thAYJ4WqG6PbGl4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"8f71ac2e-93e8-4fc1-8217-9a87f7adb754","chatgpt-custom-gpts-weaponized-in-clickfix-social-engineering-campaign","bd4b7129-170e-47b8-b124-24f318c9260e","ChatGPT Custom GPTs Weaponized in ClickFix Social Engineering Campaign","Threat actors are exploiting the trusted reputation of AI platforms like ChatGPT by creating malicious Custom GPTs that impersonate legitimate software and instruct users to run harmful PowerShell commands. The root cause is a failure in user security awareness — victims trusted AI-generated instructions without verifying their legitimacy or understanding the risks of executing unknown commands. This attack also highlights a configuration and governance gap, as organizations lack controls over which AI tools employees interact with and what actions those tools can suggest. The consequence is direct malware installation via user-initiated execution, bypassing many traditional endpoint defenses. As AI tools proliferate, this social engineering vector will grow significantly more sophisticated and harder to detect.","**Immediate actions:**\n- Train all employees to never execute PowerShell, CMD, or terminal commands sourced from AI tools, websites, or unsolicited instructions without explicit IT approval.\n- Block or restrict access to unauthorized AI platforms and Custom GPT instances via web filtering and application allowlisting policies.\n- Alert employees to the specific ClickFix lure pattern (copy-paste command execution) through an urgent security awareness bulletin.\n\n**Long-term improvements:**\n- Establish a formal AI tool governance policy defining which AI platforms are approved for use and what types of outputs employees may act upon.\n- Implement application control policies (e.g., via Windows Defender Application Control) to prevent unauthorized MSI file execution from user-initiated downloads.\n- Integrate AI-related social engineering scenarios into regular phishing and security awareness training programs.\n\n**Detection measures:**\n- Enable PowerShell script block logging and forward logs to your SIEM to detect suspicious command execution patterns originating from user sessions.\n- Monitor endpoint telemetry for unexpected MSI installations, especially those triggered from browser or user-space processes.\n- Deploy DNS filtering to block known malicious Google Sites pages and other platforms commonly abused for payload staging.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 3: Data Protection","CIS Control 14: Security Awareness and Skills Training","CIS Control 10: Malware Defenses","CIS Control 8: Audit Log Management","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AC-3: Access Enforcement","MITRE ATT&CK T1204.002: User Execution – Malicious File","MITRE ATT&CK T1059.001: PowerShell","GDPR Article 32: Security of Processing (for EU organizations with affected users)","published","2026-09-29T14:20:43.645261+00:00","2026-09-29T14:20:43.365+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.securityweek.com\u002Fhackers-use-chatgpt-custom-gpts-in-clickfix-attacks\u002F","hackers-use-chatgpt-custom-gpts-in-clickfix-attacks-8a9397","Hackers Use ChatGPT Custom GPTs in ClickFix Attacks",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]