
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.
Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs).
Custom GPTs refer to a personalized version of ChatGPT that allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. They are hosted on the legitimate ChatGPT website with the Custom GPT name at the top.
“In the incidents we saw, victims interacted with an attacker-created Custom GPT, which was programmed to respond to their prompts with a message that included a Google Sites link,” Huntress said. “This link then brought them to a ClickFix-style attack, which led to the download and execution of a malicious MSI installer.”
The installer then initiates a DLL sideloading chain responsible for loading shellcode, which is used to launch a persistence script and a RAT payload. No less than 40 users have been infected as part of the campaign.
Attack Chain
The starting point of the attack is a sponsored result for searches like “chatgpt” on Google. The two Custom GPT links involved are:
chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6
Users who end up interacting with the Custom GPT named “Plus 5.6” are served a “Service Availability Notice” that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to “limited availability on the primary domain.”
To nudge unsuspecting users into opting for the latter option, the notice also displays the message: “We recommend using the backup domain if you need immediate access.”
Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command. The PowerShell command is used to deploy an MSI installer (“ISOSimple.msi”), which abuses a legitimate Canon-signed binary (“COTFileReadApp.exe”) to sideload a rogue DLL (“ceiinfolog.dll”).
The DLL, per Huntress, is the real Canon DLL that has been altered to load a second, unsigned DLL (“rdCore.dll”), which subsequently extracts an encrypted loader from a .WAV audio file (“Common.Integrator.Preview.wav”). While this is not the first time threat actors have smuggled their payload within audio and video file formats, WAV-hidden payloads have been previously observed in connection with Octowave Loader campaigns.

In the final stage, the loader shellcode proceeds to unpack the trojan and a persistence script from an encrypted file system (“monitor.raw”), but not before bypassing AMSI, unhooking “ntdll.dll” to sidestep user-mode monitoring by security programs, and running anti-virtual machine checks by querying CPU vendor strings against VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services.
RAT Capabilities
The trojan supports a wide range of features:
- Documents installed antivirus, Microsoft Defender status, and system profile
- Runs remote desktop sessions and screen “broadcasts”
- Captures the endpoint’s camera input, microphone, and system audio
- Recognizes 17 web browsers and can launch the default one
- Searches file contents across the system using a built-in file manager component
- Drops and runs secondary payloads (.EXE, .DLL, and .MSI) and scripts (PowerShell, batch, VBScript, and JavaScript)
“To find its C2 server, which the strings call the ‘Gate,’ the RAT uses DNS-over-HTTPS through Cloudflare, Google, and Quad9 servers,” Huntress said. “Its lookups travel inside ordinary HTTPS traffic to well-known resolvers, so they never appear in local DNS logs.”
It is suspected the server details are hidden deep inside the code in an encrypted form or retrieved at runtime. The RAT malware has also been consistently found to drop a legitimately signed binary (“GOMCam2024.exe”) that launches Google Chrome with a throwaway browser profile located in the %TEMP% directory.
Broader ClickFix Campaign Activity
The findings coincide with the discovery of multiple ClickFix-oriented campaigns in the wild:
- Phishing websites hosted on Google Sites that mimic OpenAI Codex and Anthropic Claude to establish trust and serve a fake installation prompt, using ClickFix to distribute and execute stealer malware directly in memory. The stealer can fingerprint the host and contact an external domain to fetch next-stage payloads for data and cryptocurrency wallet theft.
- A likely compromised website that uses EtherHiding to fetch JavaScript serving a ClearFake reCAPTCHA verification prompt that coerces victims into running a malicious command opening a WebDAV path to retrieve a DLL. That DLL initiates a multi-stage process dropping Amatera Stealer, which — besides siphoning sensitive data — runs three secondary payloads: a NativeAOT loader, ZigCryptoStealer, and a Go reverse TCP proxy. Another build of the stealer installs NetSupport Manager. Some of these attacks have targeted Ukrainian government systems and are attributed to a Russia-aligned activity cluster tracked as UAT-10820.
- Campaigns using malvertising, phishing emails, and a compromised retail website to direct users to a fake Cloudflare interstitial page staged on a bulletproof hosting provider (AS202412, registered to Seychelles-based OMEGATECH LTD), delivering malicious payloads including a trojanized installer that drops an infostealer, a Node.js implant, and a batch script establishing persistence through a Windows Active Setup registry key.
- A ClickFix campaign active since at least November 2025 that uses a cluster of 31 compromised business websites to display a fake CAPTCHA lure delivering a dropper, which then executes a PowerShell script to set up persistence and a C2 agent using DNS-over-HTTPS for command-and-control communications.
“Overall, threat actors continue to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT’s Custom GPT feature or through Google Sites for hosting a ClickFix attack,” Huntress said. The pattern underscores an accelerating trend in which attackers leverage the credibility of well-known AI and cloud services to lower victim suspicion and bypass traditional security controls.