Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT

Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT.
ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a GPT) is essentially a version of ChatGPT that you configure for one specific job.
Think of it as creating your own specialist assistant rather than starting from a blank ChatGPT conversation.
The setup is simple and effective. Someone searches Google for “ChatGPT,” clicks a sponsored result, and lands on a Custom GPT page at the real chatgpt.com domain. The page is titled “Plus 5.6,” designed to look like a new ChatGPT model. Interact with it in any way and it responds with a single message: the service is experiencing limited availability on its primary domain, and to continue, you need to visit a “backup domain.” That backup domain is a Google Sites page serving a fake Cloudflare CAPTCHA, and from there it’s a standard ClickFix attack: copy a command, paste it into Windows Run, press Enter. The command is a PowerShell one-liner that downloads and installs a malicious MSI.
“The campaign uses a ClickFix lure to trick victims into running PowerShell, which downloads a malicious MSI and begins a multi-stage, obfuscated infection chain.” reads the report published by Huntress. “The payload establishes resilient access through dual persistence and DLL sideloading, using a Canon-signed executable (and, in a later wave, a Stardock-signed one) to load malicious code. Huntress investigated at least 40 related incidents, including two confirmed Custom GPT-driven infections.”
Huntress reported the first Custom GPT to OpenAI, and OpenAI took it down on September 25. Just two days later, another GPT linked to the same campaign was already online.
The attack uses eight stages, with each one hiding the next. The PowerShell command uses a decimal IP address instead of the usual dotted format, which Windows accepts but some URL filters may not recognize. It then downloads a 27,000-character script made up of negative numbers. The script decodes itself in memory, so the readable code never gets saved to disk.
It then quietly installs an MSI called ISOSimple.msi. The file pretends to be an “Advanced Printer Configuration Reader” from a publisher called Softplicity and hides itself from the normal list of installed programs. Microsoft Defender detected and quarantined the MSI in at least one case. By that point, however, the malware had already created a Run key and a scheduled task, allowing the attack to continue.
The technical heart of this campaign is DLL sideloading through a legitimately signed Canon application, COTFileReadApp.exe, from Canon’s CaptureOnTouch product.
“COTFileReadApp.exe is a real Canon binary from CaptureOnTouch, and its signature checks out. Its companion, COTFileReadApp.dll, calls into Canon’s logging library, ceiinfolog.dll.” continues the report. “When a program asks for a DLL by name, Windows checks the program’s own folder first, so whatever sits next to the EXE with the right name gets loaded. That’s DLL sideloading, and it’s the door the attackers used.”
The application loads its logging library from its own folder, which is standard Windows behavior. Attackers replaced that logging library with a modified version that still exports the functions Canon expects but also imports one extra DLL that Canon never asked for, rdCore.dll, where the malicious code actually lives. Canon’s binary is genuine and its signature checks out. The logging library looks almost identical to the real one because it mostly is. The only thing that changed is one line in its import table.
From there the chain keeps going. rdCore.dll extracts an encrypted loader from a WAV audio file bundled with the installer. The file has a valid audio header and begins with real audio data, but halfway through the actual sound data stops and encrypted payload bytes start. The WAV header claims the file is about 700KB when it’s actually over 1MB. A rolling XOR cipher decodes the loader directly into memory so nothing readable ever hits the disk, and then the loader goes looking for monitor.raw, a custom encrypted archive that contains 315 folders, 806 files, a persistence script, and the final remote access trojan.
That custom archive is worth pausing on. Somebody built an entire homemade encrypted filesystem just to package and deliver a RAT past automated tooling. Each file in the archive has its own encryption key, the index itself is scrambled with per-entry salts, and none of it is readable without a master key embedded in the loader. Huntress researchers decoded the whole thing by reading the math and reimplementing the decryption, which is a considerably less convenient way to spend your time than the attackers had building it.
The RAT at the end of the chain gives attackers a lot of control. It can run remote desktop sessions, capture the screen, camera and audio, access data from 17 different browsers, search files across the system, and download or run additional payloads in nine formats. It finds its command server through DNS-over-HTTPS using Cloudflare, Google and Quad9, hiding its DNS requests inside normal HTTPS traffic and keeping them out of local DNS logs.
Soon after the Canon-based version appeared, attackers released another version using a binary signed by Stardock. The loader, persistence script and RAT were exactly the same. Only the signed application, file names and hiding technique changed. This time, the loader was hidden inside a genuine Microsoft NuGet package instead of a WAV file.
The delivery script also changed. It now removes the Mark-of-the-Web tag from the MSI before launching it, which gets rid of the warning that the file came from the internet and allows the malware to run without triggering a SmartScreen prompt.
This isn’t the first time AI platforms have been used this way. Huntress has previously tracked attackers abusing shared ChatGPT and Grok conversations to push macOS malware, a sponsored Google result leading to a malicious Claude conversation that deployed a stealer, and a fake Claude Artifact impersonating a Claude Desktop download page. These campaigns typically stay live for hours or days before the provider removes them, which is long enough to hit dozens of people.
The detection advice from Huntress is worth taking seriously: look for PowerShell launching msiexec on a GUID-named MSI in the temp folder, Canon or Stardock binaries running from a fake product folder under AppData, and a Run key or scheduled task that comes back after you delete it. But the bigger point is the last one in the report: ‘Detections tied to Canon or Stardock names will miss the next swap.’
The behaviors carry over between versions. The signed binary changes. The names change. The actual attack sequence, PowerShell to msiexec to signed-app sideload to persistence to RAT, has stayed consistent across every variant Huntress analyzed, and that’s where detection needs to live.
“Overall, threat actors continue to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT’s Custom GPT feature or through Google Sites for hosting a ClickFix attack.” concludes the report. “This campaign tricked dozens of victims to run PowerShell and install a malicious payload.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, ChatGPT Custom GPTs)

