Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Attackers used ChatGPT Custom GPTs and ClickFix lures to sideload a RAT through a Canon-signed binary, hitting at least 40 users.
Huntress reported a late-September 2026 campaign in which attacker-built ChatGPT Custom GPTs, advertised on Google and titled Plus 5.6, sent victims to a Google Sites page. That page used a Cloudflare-branded ClickFix lure to make users run PowerShell, which silently installed the malicious MSI ISOSimple.msi. The installer sideloaded a malicious DLL through the legitimate Canon-signed COTFileReadApp.exe, then created a Run key and a scheduled task both named Canon Configuration Reader before unpacking a remote access trojan. Huntress linked at least 40 incidents to the Google Sites domain, including two confirmed Custom GPT cases; OpenAI removed the first GPT on September 25, but a replacement was still active on September 27.