malware
Published 2026-09-28
Verified 2026-09-29

ChatGPT Custom GPTs (Huntress 28 Sep): “Plus 5.6” Google-ads lure → ClickFix PowerShell → MSI / DLL sideload RAT

Huntress (published 28 September 2026; SecurityWeek amplify 29 Sep) documents attackers abusing ChatGPT Custom GPTs to deliver ClickFix lures and a multi-stage RAT. Victims searching Google for ChatGPT were served a sponsored result for a Custom GPT titled “Plus 5.6” (community builder) that steered users to a Google Sites “backup domain” with a fake Cloudflare CAPTCHA / ClickFix page instructing PowerShell that downloaded a malicious MSI. First chain: Canon-signed app DLL sideload, User Run key + scheduled task posing as “Canon Configuration Reader”, loader in obfuscated audio archive, DNS-over-HTTPS C2 via Cloudflare/Google/Quad9. Second Custom GPT (after OpenAI removed the first on 25 Sep; second seen 27 Sep) switched to Stardock executable/DLL sideload and a loader inside a Microsoft NuGet package; final RAT payload unchanged. Huntress: at least ~40 users infected; at least two incidents tied to a Custom GPT instance; campaign still active as of publication. Distinct from desk psychedelic-stealer-clickfix-20260924 / other ClickFix loader cards (different delivery via Custom GPT + Google ads). Primary: Huntress; wire: SecurityWeek 29 Sep.

Product
OpenAI ChatGPT Custom GPTs (abused for social engineering) + Windows ClickFix → MSI/DLL-sideload RAT
Versions
n/a (abuse of Custom GPT feature; OpenAI removed first malicious GPT 25 Sep 2026; second observed 27 Sep)
Exploited in Australia?
unknown
Patch to
No CVE. Users: prefer chatgpt.com from bookmarks (not Google ads); treat Custom GPTs marked “community builder” as untrusted; never run PowerShell/“CAPTCHA fix” clipboard commands from web pages. Defenders: block ClickFix PowerShell patterns; alert on Canon/Stardock sideload + odd scheduled tasks; monitor DoH C2; report abusive GPTs to OpenAI. Distinct from other desk ClickFix stealer cards.

Primary: Huntress — Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix (28 Sep 2026) · Vendor: Huntress blog (researcher primary) · SecurityWeek — Hackers Use ChatGPT Custom GPTs in ClickFix Attacks (29 Sep 2026)

ai identity network