Attackers are exploiting ChatGPT’s Custom GPT feature to mimic official tools and deceive users into downloading a remote access trojan (RAT), based on recent findings from Huntress. The malicious campaign deploys a hybrid ClickFix-style framework combining malvertising, fake verification prompts, obfuscated PowerShell scripts, deceptive MSI packages, and DLL sideloading.
How the Attack Unfolds
At least 40 incidents have been identified where threat actors used Google Sites to host the initial infection vector. In two cases, attackers even created fraudulent Custom GPTs to initiate the chain. One such fake GPT was named “Plus 5.6,” clearly designed to resemble legitimate official models, though its tie to a “community builder” betrays its illegitimacy.
The user journey starts when someone searches for “chatgpt” and clicks on a sponsored result that leads them to a counterfeit chatgpt.com page. There, a bogus “Service Availability Notice” redirects them to a backup site. This site shows a sham CAPTCHA verification prompt, which instructs users to copy and paste a PowerShell command.
RAT Installation and Capabilities
The command pulls down an obfuscated PowerShell script, which resolves a decimal-form IP address to evade simple filters. This script downloads an MSI file named ISOSimple.msi, installs it silently, then erases itself. The MSI masquerades as “Advanced Printer Configuration Reader” and hides its tracks by installing under %LOCALAPPDATA% while avoiding visibility in standard program lists.
Once installed, the package uses a signed executable (initially Canon’s and later Stardock’s) to load a tampered DLL. The payload triggers a DLL sideloading method that leads to execution of loader code concealed within an audio-named file. Inside memory execution follows, including AMSI bypasses, anti-virtual machine checks, and more, before ultimately delivering a fully functioning RAT capable of remote access, surveillance, file operations, and further code delivery. The malware leverages DNS-over-HTTPS through services like Cloudflare, Google, and Quad9 for command-and-control communications.
What’s Different in the Second Wave
After OpenAI removed the initial fake GPT around September 25, a new version emerged on September 27, retaining the RAT but changing its persistence strategy. The signed host executable shifted (from Canon’s to Stardock’s DeElevate64.exe), the loader was moved into a Microsoft NuGet-style package labeled Build.dat, and the installation process was altered to avoid role markers like “Mark-of-the-Web.” Despite these changes, core malicious behaviors remained largely intact.
Detect & Prevent: What to Watch For
Labels like “Canon Configuration Reader,” odd GUID-named MSI files in %TEMP%, and executable launches from %LOCALAPPDATA% that don’t align with standard app behavior are high-risk indicators. Also watch for DLLs that are unsigned or have mismatched checksums next to signed executables, Run keys or scheduled tasks with persistent names, and unprompted PowerShell commands appearing in browsing contexts claiming to be CAPTCHA or service verification.
Users should never paste PowerShell commands from service pages posing as verification steps. True verification never requires handing over control to the shell.
The investigation credits a team of cybersecurity experts, who documented every stage—from fake GPT lures through RAT deployment. The technical write-up establishes how attackers rotated hosts, signed applications, and packaging methods to bypass detection.
Analytically, this highlights a sharp shift in how adversaries weaponize AI platforms: leveraging user trust in branded name recognition like “ChatGPT” and “Cloudflare” to mask nefarious behavior. Custom GPT creation becomes a new attack surface. Organizations must stiffen prompt validation, enforce stricter detection of execution chains, and enhance user education so individuals can distinguish genuine service requests from social-engineering tricks. Watch how platform providers respond: rapid takedowns help, but the agility of attackers demands more proactive defenses.