Threat · curated 29 Sep 2026
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
First reported huntress.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Abusing custom GPTs hosted on ChatGPT.com lends attacker-controlled instructions the legitimacy of a trusted AI platform, increasing the odds victims execute malicious commands and showing how deployed AI features become malware-delivery infrastructure.
Attackers abused OpenAI's Custom GPTs feature to impersonate legitimate product offerings and route victims from the trusted ChatGPT.com domain to a malicious Google Sites 'backup' page, which used a ClickFix lure (a fake Cloudflare check) to trick users into running a PowerShell command. Huntress found the campaign deployed a remote access trojan with remote desktop, audio/camera capture, and reconnaissance capabilities; a malicious GPT named 'Plus 5.6' was one of at least two tied to the campaign, and OpenAI took down the first by September 25.
Summary
Huntress reported a malicious campaign in which a threat actor abused OpenAI's ChatGPT Custom GPTs feature to lend legitimacy to a ClickFix attack that ultimately deployed a remote access trojan. Custom GPT variants promoted in sponsored Google results directed victims to a fake 'backup' site hosted on Google Sites.[0][2]
The backup page presented a fake Cloudflare verification and instructed visitors to run a PowerShell command, which installed a malicious MSI that side-loaded a modified DLL alongside a legitimate signed application to load a RAT capable of remote desktop, audio/camera capture, file search, reconnaissance, and running further payloads.[0]
Huntress investigated at least 40 incidents connected to the Google Sites page but confirmed only two involved a custom GPT variant. OpenAI removed the first GPT by September 25; a second linked GPT appeared September 27 and was still live at publication, with later attacks swapping the Canon-signed host binary for a Stardock-signed one while keeping the same payload.[0]
Attack chain
- Delivery / Lure: Sponsored Google results promote custom ChatGPT variants (e.g., 'Plus 5.6') that impersonate legitimate product offerings and direct users to an alleged backup site hosted on Google Sites, with malicious instructions hosted on the legitimate ChatGPT.com domain to build trust.[0][2]
- ClickFix social engineering: The Google Sites backup page shows a fake Cloudflare check and instructs the visitor to run a PowerShell command locally.[0]
- Execution: The PowerShell command pings msiexec.exe to silently launch a malicious MSI installer from the temporary folder.[0]
- Loading / DLL side-loading: The MSI launches a legitimate signed application (Canon-signed, later Stardock-signed) from an unusual folder under %LOCALAPPDATA%\Programs\ that loads a modified DLL to run the malware.[0]
- Concealment (phase 6): A custom encrypted file system — a homemade encrypted archive with a small header, an index of 1,128 entries, and back-to-back file contents — conceals the persistence script and RAT, with most of the chain running in memory or via benign-looking files.[0][2]
- Persistence: The malware creates a Windows Registry Run key and a scheduled task, both named 'Canon Configuration Reader,' which reappear if deleted.[0]
- Objective / RAT: The deployed remote access trojan provides remote desktop access, audio and camera capture, file searches, host reconnaissance, and the ability to run additional payloads.[0]
Disclosure timeline
| Date | Event |
|---|---|
| 2026-09-25 | OpenAI took down the first malicious custom GPT linked to the campaign.[0] |
| 2026-09-27 | Huntress researchers discovered a second custom GPT tied to the same campaign, still active at the time of reporting.[0] |
| 2026-09-28 | Huntress published its analysis of the campaign.[2] |
| 2026-09-29 | BleepingComputer reported on the Huntress findings.[0] |
| 2026-12-11 | OpenAI plans to retire custom GPTs (the abused feature).[0] |
How it works
There is no software vulnerability being exploited; the campaign abuses the legitimate Custom GPTs feature that lets users publish tailored ChatGPT variants combining instructions, extra knowledge, and skills. Because the malicious instructions are hosted on the legitimate ChatGPT.com domain, victims are more likely to trust and follow them.[0]
Execution relies on tricking the user into running a PowerShell command from a ClickFix page. The command silently launches a malicious MSI via msiexec.exe from the temporary folder, which starts a legitimate signed application from an unusual folder under %LOCALAPPDATA%\Programs\ and side-loads a modified DLL that loads the RAT.[0]
Concealment uses a custom encrypted archive format: a small header followed by an index of 1,128 entries (each recording its parent, size, and per-file key) and then file contents packed back to back, hiding the persistence script and RAT while most activity runs in memory.[0]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| OpenAI ChatGPT Custom GPTs | Publicly published custom GPT variants (e.g., 'Plus 5.6'); the feature is being abused rather than a vulnerable version being exploited | OpenAI removed identified malicious GPTs and plans to retire the custom GPTs feature on December 11[0] |
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| registry-key | Run key named 'Canon Configuration Reader' | Persistence mechanism created by the malware; a matching Run value and scheduled task reappear if deleted.[0] |
| other | Scheduled task named 'Canon Configuration Reader' | Persistence scheduled task paired with the Run key; recreates itself if removed.[0] |
| file-path | %LOCALAPPDATA%\Programs\ | A legitimate signed application (Canon- or Stardock-signed) starting from this unusual folder is a sign of compromise per Huntress detection opportunities.[0] |
| other | Malicious custom GPT named 'Plus 5.6' | Custom ChatGPT variant used to direct victims to the malicious Google Sites backup page.[0] |
Key takeaways
- Abusing OpenAI's Custom GPTs to host malicious instructions on the trusted ChatGPT.com domain is a novel evolution of ClickFix lures that increases victim trust and follow-through.[0][2]
- The campaign is actively evolving — swapping signed host binaries (Canon to Stardock) and changing loader concealment while retaining the same RAT payload — so detections should focus on process behavior and persistence artifacts rather than static file signatures.[0]
Defensive actions
- Monitor for PowerShell invoking/pinging msiexec.exe to silently launch an MSI installer from the temporary folder.: This process behavior is a core detection opportunity because most of the infection chain runs in memory or via benign-looking files, so process activity monitoring is the reliable detection surface.[0]
- Alert on a signed application executing from an unusual folder under %LOCALAPPDATA%\Programs\.: The attack side-loads a modified DLL by launching a legitimate signed binary (Canon- or Stardock-signed) from this atypical location.[0]
- Hunt for and remediate a Run key and scheduled task both named 'Canon Configuration Reader,' watching for their recreation.: These paired persistence artifacts reappear if deleted, indicating active RAT persistence.[0]
- Treat ClickFix-style pages instructing users to paste and run PowerShell commands (including fake Cloudflare checks) as malicious, and educate users against running such commands.: The campaign relies on victims manually executing a PowerShell command from a fake backup site to start the infection chain.[0]