Hackers Weaponizing ChatGPT’s Custom GPT Feature to Trick Victims into Installing Malware
Huntress details a ClickFix campaign abusing ChatGPT Custom GPTs to push obfuscated PowerShell, malicious MSI, and DLL sideloading into a full-featured RAT.
Huntress investigated at least 40 incidents where a malicious Custom GPT named 'Plus 5.6' redirected users to a Google Sites fake CAPTCHA page instructing them to paste a PowerShell command; the script encoded its C2 IP as decimal 1614733393 (96.62.224.81) and silently installed ISOSimple.msi. The MSI launched Canon-signed COTFileReadApp.exe, which sideloaded a modified ceiinfolog.dll pulling rdCore.dll and extracting an encrypted loader from a WAV file, with AMSI bypass, ntdll unhooking, and anti-VM checks before in-memory .NET RAT execution. The RAT persists via an HKCU Run key and scheduled task, supports remote desktop, camera/microphone capture, file search, and additional payload execution, and resolves C2 via DNS-over-HTTPS. After OpenAI removed the GPT, a replacement used Stardock-signed DeElevate64.exe and a NuGet-packaged loader with Mark-of-the-Web stripped.
- Fake 'Plus 5.6' Custom GPT lures users to fake CAPTCHA page instructing PowerShell command execution.
- Obfuscated PowerShell encodes C2 IP as decimal integer, silently installs MSI masquerading as printer configuration tool.
- Canon-signed binary sideloads DLL chain extracting loader from WAV; AMSI bypass and ntdll unhooking precede RAT.
- RAT persists via HKCU Run key and scheduled task, supports desktop, camera, microphone, and payload execution.
- Post-takedown wave switched to Stardock-signed host and NuGet-packaged loader stripping Mark-of-the-Web.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | chatgpt.com | gle for “chatgpt” and click a sponsored result leading to a chatgpt.com address. Attackers named their Custom GPT “Plus 5.6,” makin |
Full article642 words · extracted from cybersecuritynews.com · click to collapse
Hackers are abusing ChatGPT’s Custom GPT feature to impersonate AI products and trick users into installing a sophisticated remote access trojan (RAT), according to Huntress researchers.
The campaign turns a trusted ChatGPT-hosted page into the opening stage of a ClickFix attack, combining malvertising, fake verification prompts, obfuscated PowerShell, malicious MSI packages, and DLL sideloading.
Huntress investigated at least 40 incidents using the campaign’s Google Sites infrastructure, including two infections traced to malicious Custom GPTs.
The attack sometimes begins when users search Google for “chatgpt” and click a sponsored result leading to a chatgpt.com address. Attackers named their Custom GPT “Plus 5.6,” making it resemble an official model, although the page identified its creator as a “community builder.”
Interaction generated a “Service Availability Notice” claiming the primary domain had limited availability and directing the visitor to a supposed backup site.
That link opened a Google Sites page dressed as a ChatGPT and Cloudflare CAPTCHA verification screen. Instead of performing legitimate verification, the ClickFix lure instructed victims to paste and execute a PowerShell command.
Microsoft describes ClickFix as a social-engineering technique that exploits users’ willingness to resolve minor errors or complete CAPTCHA checks by making them run malicious commands themselves.

According to research published by Huntress, the command downloaded a heavily obfuscated PowerShell script into the Windows temporary directory.
Huntress found that the server address was represented as the decimal value 1614733393, which Windows resolves to 96.62.224[.]81, potentially evading filters looking only for dotted IP addresses.
After decoding two layers of integer-based obfuscation, the script fetched ISOSimple.msi, installed it silently with msiexec and deleted itself.
The MSI masqueraded as “Advanced Printer Configuration Reader,” hid itself from Programs and Features, and installed under %LOCALAPPDATA%\Programs. It launched Canon’s legitimately signed COTFileReadApp.exe, which loaded a modified ceiinfolog.dll from the same directory.
This DLL sideloading chain pulled in rdCore.dll, extracted encrypted loader code concealed inside Common.Integrator.Preview.wav and executed it in memory.

The loader implemented an AMSI bypass, ntdll unhooking, anti-virtual-machine checks, and in-memory .NET execution before opening monitor.raw, a custom encrypted archive containing persistence logic and the final RAT.
The malware created an HKCU Run value and scheduled task named “Canon Configuration Reader,” repeatedly rebuilding them if removed.
Its RAT supports remote desktop access, camera and microphone capture, file searches, browser launching, system reconnaissance, and additional EXE, DLL, MSI, PowerShell, or script payload execution. It resolves command-and-control infrastructure using DNS-over-HTTPS through Cloudflare, Google, and Quad9.
After OpenAI removed the first reported GPT by September 25, Huntress found a replacement on September 27. The newer wave retained the same RAT but replaced Canon’s executable with Stardock-signed DeElevate64.exe, moved the loader into a Microsoft NuGet package named Build.dat and stripped Mark-of-the-Web before installation.
Defenders should prioritize behavioral detection over product names because attackers can rotate signed host applications.
High-value signals include PowerShell spawning msiexec for GUID-named MSI files in %TEMP%, signed Canon or Stardock binaries launched from unexpected %LOCALAPPDATA%\Programs paths, matching Run-key and scheduled-task names, and unsigned or checksum-modified DLLs beside legitimate executables.
Users should immediately close any CAPTCHA or AI service page that asks them to open PowerShell, Terminal, or the Run dialog and paste a command; legitimate verification checks do not require shell execution.
The research credits Tanner Filip, Camilo Lima, Ethan Williams, Ryan Eisenhower, Jose Oregon, Jai Minton, Susannah Matt, and Lindsey Welch for contributing to the investigation and technical write-up.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.