Threat actors have found a new way to turn a trusted platform into a malware delivery system, and this time they are using ChatGPT Custom GPTs to disguise their payloads as legitimate product offerings, then steering victims toward malicious sites that use ClickFix lures to infect their machines.
Huntress observed the activity in late September 2026, and it marks yet another abuse of a feature inside a trusted AI platform, because prior campaigns have already weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans.
Custom GPTs are personalized versions of ChatGPT that let users define custom instructions, upload reference files, and enable specific skills without writing any code, and they are hosted on the legitimate ChatGPT website with the Custom GPT name displayed at the top, which is exactly what makes them so effective as a lure.
Quick Summary
|
What |
Details |
|
Campaign |
ChatGPT Custom GPTs malware distribution |
|
Observed By |
Huntress |
|
Timing |
Late September 2026 |
|
Method |
Custom GPT → Google Sites → ClickFix |
|
Payload |
MSI installer, DLL sideloading, RAT |
|
Infections |
40+ users |
How the Attack Unfolds
In the incidents Huntress observed, victims interacted with an attacker-created Custom GPT that was programmed to respond to their prompts with a message containing a Google Sites link, and that link then brought them to a ClickFix-style attack, which led to the download and execution of a malicious MSI installer.
The installer then initiates a DLL sideloading chain responsible for loading shellcode, which is used to launch a persistence script and a RAT payload, and no fewer than 40 users have been infected as part of this campaign.
The starting point is a sponsored result for searches like "chatgpt" on Google, and the two Custom GPT links Huntress listed are chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6 and chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6.
The Lure Inside the Custom GPT
Users who end up interacting with the Custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain," and to nudge unsuspecting users toward the latter option, the notice also displays the message recommending the backup domain if they need immediate access.
Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command.
The PowerShell command is used to deploy an MSI installer called ISOSimple.msi, which abuses a legitimate Canon-signed binary called COTFileReadApp.exe to sideload a rogue DLL called ceiinfolog.dll.
The Sideloading Chain
According to Huntress, the DLL is the real Canon DLL that has been altered to load a second, unsigned DLL called rdCore.dll, which subsequently extracts an encrypted loader from a .WAV audio file called Common.Integrator.Preview.wav.
While this is not the first time threat actors have smuggled their payload within audio and video file formats, WAV-hidden payloads have been previously observed in connection with Octowave Loader campaigns, so this is a technique with a track record.
In the final stage, the loader shellcode proceeds to unpack the trojan and a persistence script from an encrypted file system called monitor.raw, but not before bypassing AMSI, unhooking ntdll.dll to sidestep user-mode monitoring by security programs, and running anti-virtual machine checks by comparing CPU vendor strings against various VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services.
What the RAT Can Do
The trojan supports a wide range of features, and the list is long enough to be concerning.
|
Feature |
What It Does |
|
System profiling |
Documents installed antivirus, Defender status, system profile |
|
Remote desktop |
Runs remote desktop sessions and screen broadcasts |
|
Audio and video |
Captures camera input, microphone, and system audio |
|
Browser control |
Recognizes 17 browsers and can launch the default one |
|
File search |
Searches file contents using a built-in file manager |
|
Secondary payloads |
Drops and runs EXE, DLL, MSI, and scripts |
|
C2 resolution |
Uses DNS-over-HTTPS through Cloudflare, Google, and Quad9 |
The RAT uses DNS-over-HTTPS to find its command-and-control server, which the strings call the "Gate," and its lookups travel inside ordinary HTTPS traffic to well-known resolvers, so they never appear in local DNS logs.
It is suspected the server details are hidden deep inside the code in an encrypted form or retrieved at runtime, and the RAT has consistently been found to drop a legitimately signed binary called GOMCam2024.exe that launches Google Chrome with a throwaway browser profile located in the %TEMP% directory.
Other ClickFix Campaigns in the Wild
The findings coincide with the discovery of multiple ClickFix-oriented campaigns, and the breadth of activity suggests this technique is being widely adopted.
- One campaign uses phishing websites hosted on Google Sites that mimic OpenAI Codex and Anthropic Claude to establish trust and serve a fake installation prompt, which uses ClickFix to distribute and execute stealer malware directly in memory, and the stealer can fingerprint the host and contact an external domain to fetch next-stage payloads for data and cryptocurrency wallet theft.
- Another involves a likely compromised website that uses EtherHiding to fetch JavaScript that serves a ClearFake reCAPTCHA verification prompt to coerce victims into running a malicious command that opens a WebDAV path and retrieves a DLL, and the DLL payload initiates a multi-stage process to drop Amatera Stealer, which besides siphoning sensitive data runs three secondary payloads including a NativeAOT loader, ZigCryptoStealer, and a Go reverse TCP proxy, and another build installs NetSupport Manager, and some of these attacks have targeted Ukrainian government systems and are attributed to a Russia-aligned cluster tracked as UAT-10820.
- A third campaign uses malvertising, phishing emails, and a compromised retail website to direct users to a fake Cloudflare interstitial page staged on a bulletproof hosting provider registered to Seychelles-based OMEGATECH LTD, delivering malicious payloads including a trojanized installer that drops an infostealer, a Node.js implant, and a batch script that establishes persistence through a Windows Active Setup registry key.
- A fourth campaign has been active since at least November 2025 and uses a cluster of 31 compromised business websites to display a fake CAPTCHA lure that delivers a dropper, which then executes a PowerShell script to set up persistence and a C2 agent that employs EtherHiding by querying the Polygon blockchain to identify the C2 server and then uses it to receive and execute arbitrary PowerShell commands.
GuidePoint Security noted that what began as a general-purpose remote-access backdoor has since been observed delivering a real-time banking trojan capable of intercepting login credentials and two-factor codes from major banks and cryptocurrency exchanges as victims type them.
What You Should Do
- Warn users that sponsored search results for ChatGPT can lead to malicious Custom GPTs, and that the legitimate ChatGPT website is the only place to access official GPTs.
- Treat any Custom GPT that directs you to a Google Sites link or asks you to run a command as suspicious, because that is not how legitimate OpenAI features work.
- Block or monitor the Custom GPT links listed above if they appear in your environment.
- Hunt for the MSI installer ISOSimple.msi, the DLLs ceiinfolog.dll and rdCore.dll, and the WAV file Common.Integrator.Preview.wav.
- Check for the signed binary GOMCam2024.exe launching Chrome with a profile in %TEMP%, because that is a known indicator.
- Monitor DNS-over-HTTPS traffic to Cloudflare, Google, and Quad9 resolvers if you do not have a legitimate business need for it.
- Educate users about ClickFix, because the attack depends on tricking them into running a command.
The Bottom Line
Threat actors are abusing ChatGPT Custom GPTs to disguise malicious offerings and direct victims to ClickFix lures that deliver a multi-stage malware infection, and while the campaign has infected over 40 users so far, the technique is spreading across multiple ClickFix campaigns that use Google Sites, EtherHiding, and compromised websites, so defenders need to treat trusted platforms as potential entry points and train users to recognize when a legitimate service is being impersonated.
Quick Reference
|
Key Point |
Detail |
|
Campaign |
ChatGPT Custom GPTs malware distribution |
|
Observed By |
Huntress |
|
Method |
Custom GPT → Google Sites → ClickFix |
|
Payload |
MSI installer, DLL sideloading, RAT |
|
Infections |
40+ users |
|
Related Activity |
Google Sites phishing, EtherHiding, ClearFake |
What to Do
- Warn users about sponsored ChatGPT search results
- Treat Google Sites redirects from Custom GPTs as suspicious
- Block the two Custom GPT links
- Hunt for ISOSimple.msi, ceiinfolog.dll, rdCore.dll
- Check for GOMCam2024.exe launching Chrome in %TEMP%
- Monitor DNS-over-HTTPS traffic
- Educate users about ClickFix
FAQ Section
What is the ChatGPT Custom GPTs malware campaign?
It is a campaign where threat actors create Custom GPTs that respond to prompts with Google Sites links, which lead to ClickFix attacks that deliver a multi-stage malware infection.
How can the victims find these malicious Custom GPTs?
They can access these via sponsored results by Google searches using keywords like "chatgpt", which are embedded within the legitimate ChatGPT website.
What occurs when the victim clicks the Google Sites link?
A fake Cloudflare CAPTCHA verification process is launched which sets off a ClickFix attack, compelling the victim to execute a malicious PowerShell command.
What malware is delivered?
An MSI installer called ISOSimple.msi abuses a Canon-signed binary to sideload a rogue DLL, which loads shellcode from a WAV file and ultimately deploys a RAT with extensive surveillance and control features.
How many users have been infected?
Huntress observed no fewer than 40 users infected as part of this campaign.
What should I do to protect my organization?
Warn users about sponsored search results, treat Google Sites redirects from Custom GPTs as suspicious, hunt for the listed indicators, and educate users about ClickFix.