// AI threat desk · 1 Oct 2026
Home/AI-ATK · AI-Powered Attacks
AI-Powered AttacksHighRAT

Hackers abuse ChatGPT custom GPTs with ClickFix trick to drop RAT, over 40 hit

Security firm Huntress says attackers posed as a product promotion custom GPT on ChatGPT in late Sep 2026, luring users to a fake Cloudflare check page via Google Sites, then using ClickFix to install a remote access trojan. At least 40 users were hit.

Illustration: a user facing a suspicious pop-up verification prompt on a computer.
File photo: Illustration: a user facing a suspicious pop-up verification prompt on a computer.. Photo: rawpixel (CC0)
Key takeaways
  • Huntress says attackers built a ChatGPT custom GPT named ‘Plus 5.6’ that posed as a service availability notice to direct users to a backup domain hosted on Google Sites
  • The campaign tied to that Google Sites domain has caused at least 40 incidents, two of which were confirmed to have started through the custom GPT
  • Victims were tricked on a fake Cloudflare verification page into running a PowerShell command, which eventually deployed a remote access trojan (RAT) through an eight-stage infection chain
On this page

The attack starts with a Google search ad

According to Huntress’ investigation report, attackers created a custom GPT named ‘Plus 5.6’ on the ChatGPT platform in late September, aiming to make victims believe they were talking to the real ChatGPT model.

Most victims reached the page by clicking a sponsored result with Google Ads tracking parameters when searching ‘chatgpt’ on Google. The custom GPT was set to respond to any question with a ‘service availability notice’, claiming the main domain had limited service and suggesting users upgrade their subscription or switch to a ‘backup domain’ for instant access.

Fake Cloudflare verification page triggers ClickFix attack

The so-called backup domain was actually a page hosted on Google Sites, disguised as a Cloudflare CAPTCHA verification screen. The report says users were tricked into copying and pasting a PowerShell command into a terminal to run it, a classic ClickFix attack technique.

The command silently downloads and installs a malicious MSI installer (ISOSimple.msi) disguised as ‘Advanced Printer Configuration’. It abuses a legitimate application signed by Canon (COTFileReadApp.exe) to side-load a malicious DLL. The process sets up two persistence mechanisms, both named ‘Canon Configuration Reader’.

Eight-stage infection chain ends with RAT deployment

Huntress points out that the entire infection chain spans eight stages, each designed to hide the next. The tampered Canon DLL loads a helper that extracts an encrypted loader from a .WAV audio file (Common.Integrator.Preview.wav), then unpacks the trojan and persistence scripts from an encrypted file system named monitor.raw.

Before launching the final stage, the malware bypasses AMSI and removes the monitoring hook on ntdll.dll to evade user-mode detection by security software. It also checks the CPU vendor string to detect virtual machine environments including VMware, VirtualBox, Hyper-V, QEMU, Xen and Parallels.

The final RAT has broad functionality, including logging installed antivirus software and Microsoft Defender status, starting remote desktop sessions, capturing webcam and microphone feeds, identifying 17 browsers, and downloading and executing further-stage EXE, DLL, MSI files and various scripts.

After Huntress reported the custom GPT to OpenAI, OpenAI removed it on Sep 25. But researchers found on Sep 27 that a new custom GPT linked to the same campaign was still available, showing attackers continue to rely on this technique for social engineering.

Huntress describes this as another case of threat actors turning a trusted platform into a social engineering entry point. Earlier campaigns abused Claude Artifacts and ChatGPT’s shared conversation feature to spread infostealers and RATs. The situation resembles the earlier Carbonato botnet case, which used Telegram to control AI agents, both reflecting attackers’ ongoing search for legitimate features in AI platforms that can be abused.

What to do now

  1. Stay alert to any ‘verification’ or ‘installation’ prompt reached through search ads, chatbots or collaboration platform links, especially pages asking you to copy and paste commands into a terminal or PowerShell
  2. Block known malicious indicators in endpoint protection, including the Google Sites domain and decoded C2 host in this case
  3. Apply enterprise-level usage policies for community-built AI tools such as custom GPTs, and remind staff to watch for labels like ‘community builder’ on pages
  4. Check endpoints for scheduled tasks or Run key persistence entries named ‘Canon Configuration Reader’, and investigate whether ISOSimple.msi was ever executed

FAQ

What is a ClickFix attack?

ClickFix is a social engineering technique that tricks users into copying and pasting a command into a terminal or PowerShell to run it. It appears to fix a verification or technical issue, but actually triggers malware download and execution.

Are all ChatGPT users affected?

No. Those affected are users who clicked a specific attacker-created custom GPT through Google search ads and followed its link to a fake page on Google Sites. The incidents confirmed by Huntress are tied to that specific Google Sites domain.

How did attackers use the Canon-signed program?

According to the Huntress report, the malicious MSI installer deploys a legitimate application digitally signed by Canon (COTFileReadApp.exe) and uses it to side-load a tampered DLL, helping to evade some security detection.

Is this custom GPT still usable now?

The originally reported custom GPT was removed by OpenAI on Sep 25. But Huntress says on Sep 27 it found a new custom GPT linked to the same campaign still active, showing the threat persists.

Sources

  1. Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures, HuntressPrimary
Explore with AI