Huntress: Malicious Custom GPTs distribute remote-access trojans
Attackers are distributing remote-access trojans by using sponsored Google search results to direct users to malicious custom GPTs, security researchers at Huntress reported on October 4, 2026.
The Tech TL;DR:
- Malicious actors deployed fake OpenAI custom GPTs via sponsored Google search ads to execute ClickFix attacks.
- The attack chain uses PowerShell to install an MSI package containing a signed application and a manipulated DLL that loads a remote-access trojan.
- OpenAI removed the initial malicious GPT by September 25, but researchers found a second active variant on September 27.
Sponsored Google Search Ads Lead Users to Malicious Custom GPT Named Plus 5.6
The campaign starts when users click sponsored Google search results that lead to a customized version of ChatGPT. According to Huntress, the malicious GPT was named “Plus 5.6” and directed visitors to a Google Sites page housing a fake Cloudflare security check. This technique, known as ClickFix, tricks users into executing a PowerShell command while relying on the legitimate domain chatgpt.com to establish credibility. Although previous threat campaigns utilized shared ChatGPT conversations for ClickFix tactics, the deployment of custom GPTs hosted directly by OpenAI marks a distinct shift in methodology.
PowerShell Scripts Deploy Remote-Access Trojan via Signed Applications
The executed PowerShell command initiates the silent installation of a malicious MSI package from the system temporary directory. This package launches a legitimate, signed application alongside a manipulated DLL designed to inject and load a remote-access trojan. The malware grants operators full desktop remote control, audio and camera recording capabilities, file searching tools, and the ability to download supplementary payloads. To maintain system persistence, the trojan establishes a registry run key and a scheduled task, both named “Canon Configuration Reader”. Initial iterations of the campaign utilized a binary signed by Canon, while subsequent attacks shifted to applications signed by Stardock. Huntress noted that the attackers conceal both the persistence scripts and the core trojan inside a custom-built, encrypted archive featuring its own directory structure and an index containing 1,128 entries, functioning effectively as a bespoke encrypted ZIP file.
Huntress Discovers Active Custom GPTs After OpenAI Removes Initial Variants
Huntress investigated at least 40 security incidents connected to the Google Sites landing page, confirming that two involved malicious custom GPTs. OpenAI removed the first offending GPT by September 25, 2026. However, researchers identified a second custom GPT operating under the same campaign parameters on September 27, 2026, which remained active during the initial investigation. Because a substantial portion of the infection vector executes directly within system memory or leverages otherwise benign files, investigators recommend that enterprise IT teams closely monitor endpoint process activity. Indicators of compromise include PowerShell executing msiexec.exe to silently install packages from temp directories, signed applications launching from non-standard paths under %LOCALAPPDATA%Programs, and registry run keys or scheduled tasks that regenerate automatically after deletion.
Disclaimer: The technical analyses and security protocols detailed in this article are for informational purposes only. Always consult with certified IT and cybersecurity professionals before altering enterprise networks or handling sensitive data.
