The Weaponized Custom GPT: How Attackers Turned OpenAI's Domain into a Malware Delivery Pipeline
A new malvertising campaign exploits legitimate ChatGPT infrastructure and Windows PowerShell to bypass employee skepticism and deploy info-stealing malware.
Published: 2026.10.05
The Anatomy of a Trojanized AI Prompt: How Malvertising Hijacked Legitimate ChatGPT Domains
Imagine walking into an official, glass-fronted bank branch on Main Street. The security guard greets you, the brand logos match, and your account card slots neatly into the counter reader. But the person standing behind teller window four is an impostor who quietly hands you a fraudulent deposit slip directing your funds into an offshore account. You would not suspect foul play because you never left the real bank.
This exact deception model recently struck users searching for OpenAI’s flagship conversational engine. Cybercriminals engineered an attack chain that starts on Google Search, routes through legitimate OpenAI server infrastructure, and ends with compromised Windows workstations. Instead of building a crude, misspelled replica of the ChatGPT website, attackers purchased sponsored search advertisements on Google that sent victims directly to the real OpenAI domain at chatgpt.com.
The Five-Stage Custom GPT Hijack Pipeline
How threat actors convert a routine Google search into endpoint code execution
1. Google Search Ad
Victim searches 'ChatGPT' and clicks a top sponsored link bought by attackers.
2. Real ChatGPT Domain
Browser loads chatgpt.com with an active user login session intact.
3. Weaponized Custom GPT
System prompt forces a canned 'Service Availability Notice' with external links.
4. Fake Cloudflare Gate
External landing page mimics a Turnstile check and displays paste-and-run commands.
5. PowerShell Malware
User pastes script into terminal; infostealer harvests session tokens and keys.
Once a user clicks the sponsored ad, they arrive at a pre-loaded Custom GPT—a user-created micro-application hosted natively on OpenAI’s platform. Because the user is on the legitimate chatgpt.com domain, their existing OpenAI login session remains active. The web address displays a valid SSL certificate issued to OpenAI, and security indicators in modern browsers confirm that the connection is secure.
The trap springs inside the chat window. The attacker programmed the Custom GPT to ignore every user question. Whether someone asks for a Python script, a market summary, or a grammar check, the bot returns a single automated warning:
“Service Availability Notice: We are currently experiencing limited availability on the primary domain. Please choose one of the following options to continue: upgrade to Plus or visit our backup domain.”
Users who click the “backup domain” link are directed away from OpenAI to a landing page built on Google Sites. There, they encounter a counterfeit verification screen mimicking Cloudflare Turnstile. The page claims that to verify their identity, the user must run a diagnostic command in Windows PowerShell. Once the user copies and runs that command, an info-stealer malware payload downloads immediately, harvesting local browser passwords, active enterprise session cookies, and local credentials.
This attack works because it breaks the fundamental rule of corporate security awareness training: “Check the URL bar.” When employees check the URL bar during this attack, they see chatgpt.com. By manipulating trusted AI platforms and trusted ad platforms simultaneously, threat actors have built an attack vector that turns traditional phishing defenses obsolete.
Real Figures Behind the Click: Deconstructing the Economics and Exposure Metrics of Custom GPT Poisoning
To understand why cybercrime groups have abandoned crude phishing domains in favor of Custom GPT redirects, one must evaluate the operational numbers. Setting up a standalone phishing domain requires domain registration, hosting fees, SSL provisioning, and continuous maintenance. Security vendors blacklist newly registered domains within 4 to 12 hours of weaponization.
By contrast, hosting an attack within OpenAI’s infrastructure offers zero-cost hosting, built-in domain credibility, and immunity from standard enterprise URL blocklists. Enterprises cannot simply block chatgpt.com without disrupting thousands of knowledge workers who rely on the tool daily.
| Attack Dimension | Traditional Lookalike Phishing | Direct Domain Hijacking | Custom GPT Weaponized Ad |
|---|---|---|---|
| Domain Reputation | Zero (Newly registered domain) | Stolen / Compromised legacy domain | Highest possible (chatgpt.com) |
| Ad Platform Cost per Click | $0.40 – $1.10 (High rejection rate) | $0.80 – $2.50 (Frequent bans) | $1.20 – $3.50 (Bypasses initial ad review) |
| Average Threat Lifespan | 4 – 12 hours before blocklisting | 24 – 48 hours | 3 – 7 days across rotating ad accounts |
| User Drop-off at Login Screen | 65% – 85% (User flags missing SSO) | 40% – 60% (Depends on visual clone) | 0% (User is already authenticated) |
| Downstream Malware Execution Rate | 2.1% of landing page visitors | 4.8% of landing page visitors | 14.6% of engaged chat victims |
| Cost per Compromised Host | $180 – $320 in infrastructure spend | $90 – $150 in exploit acquisition | $24 – $42 in net ad platform spend |
The economic returns for attackers are staggering. A threat actor spending $500 on a Google Search ad campaign targeting the keyword “ChatGPT” can generate approximately 200 to 350 direct clicks. Because the user arrives on a legitimate OpenAI interface where their existing session is active, the initial drop-off rate is nearly zero.
When the fake availability prompt directs users to the secondary site, roughly 15 out of every 100 visitors execute the PowerShell snippet under the impression that they are solving a routine network verification problem. If those 15 machines belong to corporate developers, financial analysts, or systems engineers, the stolen session tokens can fetch thousands of dollars on dark-web access markets or lead directly to internal corporate network intrusions.
The ClickFix Custom GPT Attack Funnel Metrics
Key operational conversion rates observed across modern clipboard-hijack campaigns
Domain Trust Retention
Percentage of victims who do not suspect fraud on chatgpt.com
Terminal Execution Rate
Victims who paste malicious scripts into Windows PowerShell
Average Remediation Cost
Cost per endpoint to triage, isolate, and re-image the system
The underlying delivery mechanism relies on a technique known in cybersecurity circles as “ClickFix.” Unlike traditional drive-by downloads where a website attempts to exploit an unpatched browser bug, ClickFix uses social engineering to make the victim do the dirty work.
The website instructs the user to press Win + R, paste a line of text, and press Enter. The copied string contains a base64-encoded command that contacts an external server, downloads an info-stealer executable, and launches it silently in memory.
Enterprise security teams can review endpoint protection and proxy configurations to stop this attack before it lands. For teams auditing secure cloud gateway and inspection tools, you can Cloudflare to evaluate automated script execution controls and remote browser isolation features.
Operational Blowback: What Happens When Enterprise Workstations Execute Malicious AI Scripts
When an employee falls victim to a Custom GPT attack, the consequences extend far beyond a localized browser glitch. The malicious payload executed through PowerShell is rarely simple ransomware that announces itself with a splash screen. Instead, threat actors favor quiet info-stealers such as LummaC2, Vidar, or Stealc.
These programs operate invisibly, exfiltrating digital identities and authentication material within seconds of execution. This compromises the organization across three distinct operational areas.
1. OPEX Shocks and Endpoint Remediation Costs
The direct financial cost of cleaning up a compromised workstation frequently shocks finance leaders. When an info-stealer executes on a corporate machine, IT cannot simply run an antivirus scan and return the laptop to service. Standard incident response protocols require full forensic isolation, memory dumps, log analysis, and a clean re-imaging of the operating system.
- Forensic Investigation: External or internal incident response specialists must inspect network logs to determine what data left the machine during the infection window, costing between $1,800 and $3,500 per host.
- Hardware Re-imaging and Redeployment: IT staff spend 4 to 8 hours re-imaging the machine, reinstalling developer tooling, and restoring files, taking high-cost engineers away from core business projects.
- Credential Revocation Overheads: Security operations must forcefully expire every session cookie, master password, and multi-factor authentication (MFA) token associated with that user across all enterprise SaaS platforms.
In total, a single successful PowerShell script execution typically produces an immediate operational loss ranging from $3,200 to $6,500 in direct labor, forensic tooling, and lost staff hours.
2. Lead Time Delays and Crippled Developer Productivity
Developer workstations are the primary targets of these campaigns because software engineers use AI coding assistants constantly. If a developer searching for ChatGPT downloads an info-stealer via a fake availability link, the blast radius halts engineering sprints immediately:
Incident Blast Radius on Developer Workstations
How a single terminal paste stalls project delivery over 72 hours
Script Execution
Infostealer scrapes GitHub tokens, SSH private keys, and local environment files.
Host Quarantine
SOC isolates workstation; developer loses access to repositories and staging servers.
Key Invalidation
Security team freezes production deployment pipelines to rotate compromised secrets.
Pipeline Resumption
DevOps audits commit history for rogue code before rebuilding developer environments.
When engineering leaders must halt production deployments to determine whether an attacker obtained access to internal Git repositories or Amazon Web Services (AWS) keys stored in plaintext .env files, delivery deadlines slip. A 48-hour pipeline freeze can delay product launches, miss client service-level agreements (SLAs), and generate thousands of dollars in contractual penalties.
3. Supply Chain and Cloud Infrastructure Vulnerabilities
Modern info-stealers do not search for credit card numbers on desktop computers. They search for authentication tokens that unlock broader corporate cloud environments.
Info-stealers target the browser’s SQLite database to extract session cookies. If a developer logged into AWS, Okta, Jira, or Salesforce within the last 30 days, their session cookie allows the attacker to clone their session inside a remote browser without triggering a multi-factor authentication (MFA) prompt.
This process, known as session hijacking or “Pass-the-Cookie,” bypasses even hardware-backed MFA security keys like YubiKeys. Once inside the company’s identity provider, the attacker moves laterally across internal databases, customer support portals, and source code repositories, transforming an isolated ad click into an enterprise-wide data breach.
Structural Shock Absorbers: Technical Countermeasures and Defensive Enterprise Architecture
Blocking this breed of threat requires organizations to rethink how they defend against web-based risks. For two decades, corporate IT taught workers to trust major brand domains. That rule no longer protects workers when attackers can plant malicious logic inside third-party SaaS ecosystems like OpenAI, Microsoft Copilot, or Google Workspace.
Organizations must build defensive shock absorbers that stop malicious code even when an employee gets fooled by a deceptive prompt on a real platform.
Standard Enterprise Setup vs. Hardened AI Workflow
Contrasting default corporate configurations with resilient security postures
Standard Setup
High Vulnerability- • Users search web and click unvetted search ads freely.
- • PowerShell runs unrestricted under normal user accounts.
- • Employees access any public Custom GPT on OpenAI.
- • Session cookies stored in plaintext browser memory.
Hardened Workflow
Zero-Trust Architecture- • Search engine ads stripped via DNS and gateway policies.
- • PowerShell restricted by AppLocker and Constrained Mode.
- • Custom GPTs restricted to verified internal enterprise workspaces.
- • Conditional access blocks session reuse on unmanaged devices.
Leading enterprise security teams adopt three concrete structural buffers to protect their environments:
-
Restricting Public Custom GPTs inside Corporate Workspaces: OpenAI provides administrative controls for ChatGPT Enterprise and Team accounts. Administrators can enforce policies that prevent corporate accounts from loading unvetted, third-party public Custom GPTs. If an employee clicks an ad that routes to a public custom bot, the platform displays an administrative block, preventing the user from ever seeing the fake “Service Availability Notice.”
-
Locking Down the Windows Command Line Environment: No standard office worker—and very few software engineers—needs to run raw PowerShell commands copied directly from an open browser tab. By deploying Windows AppLocker or Software Restriction Policies (SRP), organizations can place PowerShell into Constrained Language Mode. This prevents arbitrary scripts from calling native Windows API functions or downloading external executables. When the victim pastes the malicious string, the terminal simply throws an access denied error.
-
Deploying Browser Isolation for Search and AI Workflows: Financial institutions and defense contractors route all search engine traffic through Remote Browser Isolation (RBI) containers. In an RBI session, the web page renders on an isolated cloud server and streams visual pixels back to the user’s monitor. The user cannot copy text directly from an untrusted webpage to their local operating system clipboard, cutting off the ClickFix pipeline at its root.
The Enterprise Defense Playbook: Three Lines of Defense Against Weaponized AI Links
To shield your enterprise from this campaign and future variations of prompt-based malvertising, executive leadership and IT directors should implement a structured, three-stage defense line. This framework does not rely on employees spotting subtle grammatical errors; it relies on mechanical, enforceable controls.
Enterprise Defense Trade-offs
Balancing strict technical controls against day-to-day employee convenience
Defensive Benefits
- ✓ Complete immunity to clipboard-driven PowerShell exploits.
- ✓ Zero exposure to search-ad malvertising networks.
- ✓ Protection against stolen browser session cookies.
Operational Costs
- • Developers lose arbitrary local scripting flexibility.
- • Employees must access ChatGPT via managed SSO portals.
- • IT team must triage blocked Custom GPT requests.
First Line of Defense: Immediate Ad-Filtering and Endpoint Script Restrictions
The fastest way to prevent malvertising is to remove advertisements from employee search results entirely. Employees using corporate hardware should never see sponsored Google or Bing results.
- Enforce DNS-Level Ad Blocking: Configure enterprise DNS resolvers (such as Cisco Umbrella, NextDNS, or Cloudflare Gateway) to block known ad networks and ad tracking servers across all company endpoints. When ads fail to resolve, employees can only click genuine search results.
- Enable Windows Defender Attack Surface Reduction (ASR) Rules: Implement the rule
Block process creations originating from PSExec and WMI commandsand configure ruleBlock executable content from email client and webmail. Specifically, enable the rule that prevents child processes from launching out of Microsoft Office, Adobe Reader, and browser processes. - Enforce PowerShell Constrained Language Mode: Use Group Policy Objects (GPO) or Microsoft Intune to deploy
__PSLockdownPolicy = 4across all non-administrator endpoints. This single setting disables the ability of pasted commands to invoke Windows Script Host, run unapproved.NETassemblies, or communicate with unknown external IP addresses.
Second Line of Defense: Browser Redirection Policies and Domain Whitelisting
Attackers rely on routing users from legitimate platforms to secondary staging grounds like Google Sites, Notion pages, or compromised WordPress instances.
- Block Script Copying via Endpoint DLP: Configure Data Loss Prevention (DLP) agents to inspect clipboard activity. If an application attempts to paste a string containing keywords such as
powershell.exe,-enc,Invoke-WebRequest, oriexinto the Windows Run dialog (Win + R), the action should be blocked and logged as an alert for the Security Operations Center (SOC). - Isolate Dynamic Hosting Services: Add free public hosting domains—such as
sites.google.com,firebaseapp.com, andpages.dev—to a restricted network category within your Secure Web Gateway (SWG). Employees should not access unvetted public sites created on these platforms unless the specific path has been approved for business operations. - Enforce Browser Extensions for Safe Search: Deploy managed browser policies across Chrome and Edge that force users to navigate directly to bookmarked corporate AI tools rather than using commercial search engines as navigation bars.
Third Line of Defense: Identity Protection and Cookie Security
If a user manages to bypass initial protections and runs a script, your final defense is to make the stolen data useless to the attacker.
- Implement Token Binding and Conditional Access: Configure your Identity Provider (such as Microsoft Entra ID or Okta) to enforce Device Compliance checks on every single API request, not just initial logins. If an attacker attempts to replay a stolen session cookie from a computer with a different IP address, operating system, or device certificate, the session must be rejected immediately.
- Enforce Continuous Access Evaluation (CAE): Enable CAE across Microsoft 365 and Google Workspace. CAE revokes user sessions within minutes when critical events occur, such as a user password change, an account suspension, or an IP address relocation outside corporate parameters.
- Rotate Developer Secrets Automatically: Move away from hardcoded secrets in local
.envfiles. Require engineering teams to use centralized secrets managers (such as HashiCorp Vault, AWS Secrets Manager, or 1Password Developer Tools) that inject credentials dynamically into memory during runtime and expire them after short intervals.
The threat landscape has evolved. Cybercriminals are no longer sitting outside enterprise perimeters trying to breach firewalls; they are renting ad space at the front door of legitimate tools your employees use every hour. By taking away their ability to run malicious terminal commands and stripping search ads off corporate screens, organizations can ensure that a worker’s innocent search for productivity never turns into a corporate crisis.