ChatGPT Scam Exploits Custom GPTs to Deploy Remote Access Trojan Malware on Windows Systems

5 Sources

Share

Cybersecurity researchers at Huntress discovered attackers abusing ChatGPT's Custom GPT feature to distribute malware through sponsored Google links. The scam uses a fake model called Plus 5.6 hosted on the legitimate ChatGPT.com domain, directing victims to malicious Google Sites pages with fake Cloudflare checks that deploy remote access trojan malware via PowerShell commands.

Custom GPTs Weaponized in New ChatGPT Scam Campaign

Cybersecurity researchers at Huntress have uncovered a sophisticated ChatGPT scam that exploits the platform's Custom GPT feature to distribute malware

2

. The campaign affected dozens of users, with investigators responding to at least 40 incidents connected to the malicious infrastructure

5

. Attackers created a malicious custom GPT named Plus 5.6, designed to mimic OpenAI's official model naming conventions like GPT-3.5 and GPT-5 Pro

5

. What makes this social engineering attack particularly dangerous is that Custom GPTs are hosted on the legitimate ChatGPT.com domain, lending immediate credibility to the operation and increasing the likelihood victims will follow malicious instructions

2

.

Source: BleepingComputer

Source: BleepingComputer

How the ClickFix Attack Chain Operates

The attack begins when users search for ChatGPT on Google and click on sponsored Google links that appear above authentic search results

1

. Once victims interact with the Plus 5.6 Custom GPT, they receive a Service Availability Notice regardless of what they type, claiming limited availability on the primary domain

3

. The message presents two options: upgrade to a Plus subscription or navigate to a backup domain, with the notice recommending immediate access through the backup option

3

. This backup domain is hosted on Google Sites, another trusted platform that attackers leverage to appear legitimate

2

. The Google Sites page displays fake Cloudflare checks that employ ClickFix attacks, deceiving users into copying and executing malicious PowerShell commands in Windows

3

. Roman Oliinyk, CEO of PayCore Media, Inc., emphasized that a real Cloudflare check would never ask users to do anything on their keyboard beyond checking a box or pressing a button

1

.

Source: ZDNet

Source: ZDNet

Remote Access Trojan Malware Capabilities

Executing the PowerShell command initiates installing malware through a malicious MSI installer that launches a legitimate, signed application and a modified DLL loading the payload

2

. The payload is a remote access trojan with extensive capabilities including remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads

2

. The RAT malware can view screens, search files, use webcams and microphones, capture system audio, and install more malware

4

. It documents installed antivirus software, Microsoft Defender status, and system profiles while recognizing 17 web browsers and launching the default one

3

. For persistence, the malware creates a new Run key in the Windows Registry and a scheduled task, both named Canon Configuration Reader

2

.

Advanced Evasion and Encryption Techniques

The attack chain demonstrates sophisticated technical implementation across multiple stages. Huntress researchers highlighted phase 6, noting attackers built a custom encrypted file system to conceal the persistence script and RAT malware

2

. Instead of one encrypted blob, it's a custom archive with its own folder tree, essentially a homemade encrypted zip file starting with a small header, followed by an index of 1,128 entries recording parent folders, sizes, and per-file keys, with file contents packed consecutively

2

. The RAT uses DNS-over-HTTPS through Cloudflare, Google, and Quad9 servers to find its command-and-control server, with lookups traveling inside ordinary HTTPS traffic to well-known resolvers so they never appear in local DNS logs

3

. The loader shellcode bypasses AMSI, unhooks ntdll.dll to sidestep user-mode monitoring by security programs, and runs anti-virtual machine checks by examining CPU vendor strings against various VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services

3

.

Source: Hacker News

Source: Hacker News

Evolving Campaign and Platform Response

OpenAI took down the first malicious custom GPT by September 25, but researchers discovered a second GPT linked to the same campaign on September 27 that remained active when they published their report

2

. More recent attacks switched from a Canon-signed host application to a Stardock-signed one and changed how they concealed and delivered the loader, although the payload remained the same

2

. OpenAI plans to retire Custom GPTs on December 11

2

. The campaign represents part of a broader trend where threat actors continue turning trusted platforms into convincing entry points for social engineering attacks, whether via ChatGPT's Custom GPT feature or through Google Sites for hosting ClickFix attacks

3

. Most of the infection chain runs in memory or is supported by files that appear benign, allowing defenders to implement detections based on process activity monitoring

2

. Users should type ChatGPT.com directly into browsers instead of searching for it, avoid clicking sponsored Google links, and never paste and run commands on computers unless certain of their function

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved