Tuesday, September 29, 2026
Follow on LinkedIn

Hackers Weaponizing ChatGPT’s Custom GPT Feature to Trick Victims into Installing Malware

Hackers are abusing ChatGPT’s Custom GPT feature to impersonate AI products and trick users into installing a sophisticated remote access trojan (RAT), according to Huntress researchers.

The campaign turns a trusted ChatGPT-hosted page into the opening stage of a ClickFix attack, combining malvertising, fake verification prompts, obfuscated PowerShell, malicious MSI packages, and DLL sideloading.

Huntress investigated at least 40 incidents using the campaign’s Google Sites infrastructure, including two infections traced to malicious Custom GPTs.

The attack sometimes begins when users search Google for “chatgpt” and click a sponsored result leading to a chatgpt.com address. Attackers named their Custom GPT “Plus 5.6,” making it resemble an official model, although the page identified its creator as a “community builder.”

Interaction generated a “Service Availability Notice” claiming the primary domain had limited availability and directing the visitor to a supposed backup site.

That link opened a Google Sites page dressed as a ChatGPT and Cloudflare CAPTCHA verification screen. Instead of performing legitimate verification, the ClickFix lure instructed victims to paste and execute a PowerShell command.

Microsoft describes ClickFix as a social-engineering technique that exploits users’ willingness to resolve minor errors or complete CAPTCHA checks by making them run malicious commands themselves.

ChatGPT Custom GPT ClickFix to RAT infection chain
ChatGPT Custom GPT ClickFix to RAT infection chain (Image Source: Huntress)

According to research published by Huntress, the command downloaded a heavily obfuscated PowerShell script into the Windows temporary directory.

Huntress found that the server address was represented as the decimal value 1614733393, which Windows resolves to 96.62.224[.]81, potentially evading filters looking only for dotted IP addresses.

After decoding two layers of integer-based obfuscation, the script fetched ISOSimple.msi, installed it silently with msiexec and deleted itself.

The MSI masqueraded as “Advanced Printer Configuration Reader,” hid itself from Programs and Features, and installed under %LOCALAPPDATA%\Programs. It launched Canon’s legitimately signed COTFileReadApp.exe, which loaded a modified ceiinfolog.dll from the same directory.

This DLL sideloading chain pulled in rdCore.dll, extracted encrypted loader code concealed inside Common.Integrator.Preview.wav and executed it in memory.

Canon COTFileReadApp.exe and modified ceiinfolog.dll comparison
Canon COTFileReadApp.exe and modified ceiinfolog.dll comparison (Image Source: Huntress)

The loader implemented an AMSI bypass, ntdll unhooking, anti-virtual-machine checks, and in-memory .NET execution before opening monitor.raw, a custom encrypted archive containing persistence logic and the final RAT.

The malware created an HKCU Run value and scheduled task named “Canon Configuration Reader,” repeatedly rebuilding them if removed.

Its RAT supports remote desktop access, camera and microphone capture, file searches, browser launching, system reconnaissance, and additional EXE, DLL, MSI, PowerShell, or script payload execution. It resolves command-and-control infrastructure using DNS-over-HTTPS through Cloudflare, Google, and Quad9.

After OpenAI removed the first reported GPT by September 25, Huntress found a replacement on September 27. The newer wave retained the same RAT but replaced Canon’s executable with Stardock-signed DeElevate64.exe, moved the loader into a Microsoft NuGet package named Build.dat and stripped Mark-of-the-Web before installation.

Defenders should prioritize behavioral detection over product names because attackers can rotate signed host applications.

High-value signals include PowerShell spawning msiexec for GUID-named MSI files in %TEMP%, signed Canon or Stardock binaries launched from unexpected %LOCALAPPDATA%\Programs paths, matching Run-key and scheduled-task names, and unsigned or checksum-modified DLLs beside legitimate executables.

Users should immediately close any CAPTCHA or AI service page that asks them to open PowerShell, Terminal, or the Run dialog and paste a command; legitimate verification checks do not require shell execution.

The research credits Tanner Filip, Camilo Lima, Ethan Williams, Ryan Eisenhower, Jose Oregon, Jai Minton, Susannah Matt, and Lindsey Welch for contributing to the investigation and technical write-up.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Guru Baran
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Cyber Security Guide

Latest Cyber News

Expert Talks