News / Cybersecurity
Malicious Custom GPTs on ChatGPT Spread a RAT via ClickFix Attacks Published on 29 September 2026 by Christ-loisele (3 min read)
Two Custom GPTs exploited by cybercriminals have infected at least 40 users by impersonating legitimate tools. Huntress reveals a campaign using PowerShell and MSI files to deploy an advanced trojan.
Video: How to Create Custom GPTs - Build Your Own ChatGPT (Step-by-Step Tutorial) (Creator School AI, YouTube)
A two-phase campaign with Custom GPTs removed and then replaced
Researchers from Huntress have documented a campaign where attackers created two Custom GPTs on the ChatGPT platform to trick users. The first, named ‘Plus 5.6’, mimicked a legitimate product and redirected victims to a page hosted on Google Sites simulating a Cloudflare CAPTCHA verification.
According to SecurityWeek , following a report from Huntress, OpenAI removed this Custom GPT on September 25, 2026. Two days later, a second GPT linked to the same campaign reappeared, with slightly modified mechanisms to bypass detections.
Attackers found an elegant way to weaponize Custom GPTs to bypass traditional defenses and exploit users' trust in AI tools.
Illustrative photo: network switch (Deavmi, CC BY-SA 3.0)
The ClickFix mechanism: an eight-step infection chain
Victims were prompted to run a PowerShell command via a fake warning message (‘Service Availability Notice’). This command downloaded a malicious MSI file, triggering a multi-stage infection described by IT Security Guru . The MSI sideloaded a signed Canon DLL to establish persistence through a User Run key and a scheduled task named ‘Canon Configuration Reader’. The final loader, hidden in a WAV file, deployed a Remote Access Trojan (RAT) capable of capturing audio, video, and executing remote commands.
Attackers used advanced obfuscation techniques, such as bypassing the Antimalware Scan Interface (AMSI) , system library unhooking (ntdll), and anti-virtual machine checks, according to Huntress' analysis.
What this changes here: risks for Beninese businesses and administrations
The ClickFix Attacks exploit users' trust in widely available tools, a vulnerability particularly critical for Beninese and West African businesses where the adoption of cloud solutions and AI assistants is rapidly growing. Custom GPTs, often promoted through sponsored search results, could target professionals using ChatGPT for administrative or technical tasks, encouraging them to execute malicious commands under the pretext of system updates or checks.
Public administrations, some of which rely on software signed by recognized publishers (such as Canon), could be exposed to DLL sideloading attacks if employees install updates or patches through unsecured channels. The persistence of malware via scheduled tasks or registry keys, as observed in this campaign, could compromise workstations for weeks without detection, especially if local antivirus solutions do not cover the latest evasion techniques.
Finally, the use of backup domains hosted on platforms like Google Sites could indicate a trend to bypass geographic blocks or blacklists, forcing IT teams to monitor not only direct links but also dynamic redirects in internal communications.
A rapidly evolving malicious ecosystem
The campaign combines several emerging techniques: the abuse of Custom GPTs for initial distribution, the use of misleading names (‘Plus 5.6’) to mimic legitimate software, and a segmented infection chain to avoid detection. CryptoBriefing highlights that attackers have leveraged ChatGPT’s reputation by targeting sponsored searches for the term ‘chatgpt’, thereby increasing the credibility of the decoys.
OpenAI responded by removing the first Custom GPT after it was reported, but the quick reappearance of a variant shows that cybercriminals are adapting their tactics in real time. For businesses, this underscores the importance of training users to verify the sources of links, even when they originate from official interfaces like ChatGPT, and using tools to detect anomalous behavior (such as unauthorized PowerShell executions).
Sources