Hacking

ChatGPT Custom GPTs Spread Malware via ClickFix Lures

Published  ·  9 min read

Threat actors have found a new way to turn a trusted platform into a malware delivery system, and this time they are using ChatGPT Custom GPTs to disguise their payloads as legitimate product offerings, then steering victims toward malicious sites that use ClickFix lures to infect their machines.

Huntress observed the activity in late September 2026, and it marks yet another abuse of a feature inside a trusted AI platform, because prior campaigns have already weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans.

Custom GPTs are personalized versions of ChatGPT that let users define custom instructions, upload reference files, and enable specific skills without writing any code, and they are hosted on the legitimate ChatGPT website with the Custom GPT name displayed at the top, which is exactly what makes them so effective as a lure.

Quick Summary

What

Details

Campaign

ChatGPT Custom GPTs malware distribution

Observed By

Huntress

Timing

Late September 2026

Method

Custom GPT → Google Sites → ClickFix

Payload

MSI installer, DLL sideloading, RAT

Infections

40+ users

How the Attack Unfolds

In the incidents Huntress observed, victims interacted with an attacker-created Custom GPT that was programmed to respond to their prompts with a message containing a Google Sites link, and that link then brought them to a ClickFix-style attack, which led to the download and execution of a malicious MSI installer.

The installer then initiates a DLL sideloading chain responsible for loading shellcode, which is used to launch a persistence script and a RAT payload, and no fewer than 40 users have been infected as part of this campaign.

The starting point is a sponsored result for searches like "chatgpt" on Google, and the two Custom GPT links Huntress listed are chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6 and chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6.

The Lure Inside the Custom GPT

Users who end up interacting with the Custom GPT named "Plus 5.6" are served a "Service Availability Notice" that instructs them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain," and to nudge unsuspecting users toward the latter option, the notice also displays the message recommending the backup domain if they need immediate access.

Should the victim follow through, the Google Sites domain presents a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into copying and executing a malicious PowerShell command.

The PowerShell command is used to deploy an MSI installer called ISOSimple.msi, which abuses a legitimate Canon-signed binary called COTFileReadApp.exe to sideload a rogue DLL called ceiinfolog.dll.

The Sideloading Chain

According to Huntress, the DLL is the real Canon DLL that has been altered to load a second, unsigned DLL called rdCore.dll, which subsequently extracts an encrypted loader from a .WAV audio file called Common.Integrator.Preview.wav.

While this is not the first time threat actors have smuggled their payload within audio and video file formats, WAV-hidden payloads have been previously observed in connection with Octowave Loader campaigns, so this is a technique with a track record.

In the final stage, the loader shellcode proceeds to unpack the trojan and a persistence script from an encrypted file system called monitor.raw, but not before bypassing AMSI, unhooking ntdll.dll to sidestep user-mode monitoring by security programs, and running anti-virtual machine checks by comparing CPU vendor strings against various VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services.

What the RAT Can Do

The trojan supports a wide range of features, and the list is long enough to be concerning.

Feature

What It Does

System profiling

Documents installed antivirus, Defender status, system profile

Remote desktop

Runs remote desktop sessions and screen broadcasts

Audio and video

Captures camera input, microphone, and system audio

Browser control

Recognizes 17 browsers and can launch the default one

File search

Searches file contents using a built-in file manager

Secondary payloads

Drops and runs EXE, DLL, MSI, and scripts

C2 resolution

Uses DNS-over-HTTPS through Cloudflare, Google, and Quad9

The RAT uses DNS-over-HTTPS to find its command-and-control server, which the strings call the "Gate," and its lookups travel inside ordinary HTTPS traffic to well-known resolvers, so they never appear in local DNS logs.

It is suspected the server details are hidden deep inside the code in an encrypted form or retrieved at runtime, and the RAT has consistently been found to drop a legitimately signed binary called GOMCam2024.exe that launches Google Chrome with a throwaway browser profile located in the %TEMP% directory.

Other ClickFix Campaigns in the Wild

The findings coincide with the discovery of multiple ClickFix-oriented campaigns, and the breadth of activity suggests this technique is being widely adopted.

  • One campaign uses phishing websites hosted on Google Sites that mimic OpenAI Codex and Anthropic Claude to establish trust and serve a fake installation prompt, which uses ClickFix to distribute and execute stealer malware directly in memory, and the stealer can fingerprint the host and contact an external domain to fetch next-stage payloads for data and cryptocurrency wallet theft.
  • Another involves a likely compromised website that uses EtherHiding to fetch JavaScript that serves a ClearFake reCAPTCHA verification prompt to coerce victims into running a malicious command that opens a WebDAV path and retrieves a DLL, and the DLL payload initiates a multi-stage process to drop Amatera Stealer, which besides siphoning sensitive data runs three secondary payloads including a NativeAOT loader, ZigCryptoStealer, and a Go reverse TCP proxy, and another build installs NetSupport Manager, and some of these attacks have targeted Ukrainian government systems and are attributed to a Russia-aligned cluster tracked as UAT-10820.
  • A third campaign uses malvertising, phishing emails, and a compromised retail website to direct users to a fake Cloudflare interstitial page staged on a bulletproof hosting provider registered to Seychelles-based OMEGATECH LTD, delivering malicious payloads including a trojanized installer that drops an infostealer, a Node.js implant, and a batch script that establishes persistence through a Windows Active Setup registry key.
  • A fourth campaign has been active since at least November 2025 and uses a cluster of 31 compromised business websites to display a fake CAPTCHA lure that delivers a dropper, which then executes a PowerShell script to set up persistence and a C2 agent that employs EtherHiding by querying the Polygon blockchain to identify the C2 server and then uses it to receive and execute arbitrary PowerShell commands.

GuidePoint Security noted that what began as a general-purpose remote-access backdoor has since been observed delivering a real-time banking trojan capable of intercepting login credentials and two-factor codes from major banks and cryptocurrency exchanges as victims type them.

What You Should Do

  • Warn users that sponsored search results for ChatGPT can lead to malicious Custom GPTs, and that the legitimate ChatGPT website is the only place to access official GPTs.
  • Treat any Custom GPT that directs you to a Google Sites link or asks you to run a command as suspicious, because that is not how legitimate OpenAI features work.
  • Block or monitor the Custom GPT links listed above if they appear in your environment.
  • Hunt for the MSI installer ISOSimple.msi, the DLLs ceiinfolog.dll and rdCore.dll, and the WAV file Common.Integrator.Preview.wav.
  • Check for the signed binary GOMCam2024.exe launching Chrome with a profile in %TEMP%, because that is a known indicator.
  • Monitor DNS-over-HTTPS traffic to Cloudflare, Google, and Quad9 resolvers if you do not have a legitimate business need for it.
  • Educate users about ClickFix, because the attack depends on tricking them into running a command.

The Bottom Line

Threat actors are abusing ChatGPT Custom GPTs to disguise malicious offerings and direct victims to ClickFix lures that deliver a multi-stage malware infection, and while the campaign has infected over 40 users so far, the technique is spreading across multiple ClickFix campaigns that use Google Sites, EtherHiding, and compromised websites, so defenders need to treat trusted platforms as potential entry points and train users to recognize when a legitimate service is being impersonated.

Quick Reference

Key Point

Detail

Campaign

ChatGPT Custom GPTs malware distribution

Observed By

Huntress

Method

Custom GPT → Google Sites → ClickFix

Payload

MSI installer, DLL sideloading, RAT

Infections

40+ users

Related Activity

Google Sites phishing, EtherHiding, ClearFake

What to Do

  • Warn users about sponsored ChatGPT search results
  • Treat Google Sites redirects from Custom GPTs as suspicious
  • Block the two Custom GPT links
  • Hunt for ISOSimple.msi, ceiinfolog.dll, rdCore.dll
  • Check for GOMCam2024.exe launching Chrome in %TEMP%
  • Monitor DNS-over-HTTPS traffic
  • Educate users about ClickFix

FAQ Section

What is the ChatGPT Custom GPTs malware campaign?

It is a campaign where threat actors create Custom GPTs that respond to prompts with Google Sites links, which lead to ClickFix attacks that deliver a multi-stage malware infection.

How can the victims find these malicious Custom GPTs?

They can access these via sponsored results by Google searches using keywords like "chatgpt", which are embedded within the legitimate ChatGPT website.

What occurs when the victim clicks the Google Sites link?

A fake Cloudflare CAPTCHA verification process is launched which sets off a ClickFix attack, compelling the victim to execute a malicious PowerShell command.

What malware is delivered?

An MSI installer called ISOSimple.msi abuses a Canon-signed binary to sideload a rogue DLL, which loads shellcode from a WAV file and ultimately deploys a RAT with extensive surveillance and control features.

How many users have been infected?

Huntress observed no fewer than 40 users infected as part of this campaign.

What should I do to protect my organization?

Warn users about sponsored search results, treat Google Sites redirects from Custom GPTs as suspicious, hunt for the listed indicators, and educate users about ClickFix.

Source: The  Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067