Skip to content
The AI-First Web

Attackers used a ChatGPT Custom GPT to lure users to a trojan, Huntress finds

The address was genuine. The cheapest place to intervene is the moment a user is told to paste a command.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Attackers used a ChatGPT Custom GPT to lure users to a trojan, Huntress finds

Photo: cottonbro studio / Pexels

Key finding

Incidents Huntress responded to (at least): 40 (Source: Huntress, via Help Net Security (September 29, 2026))

The address was real. The author was not.

A trusted address does not tell you who wrote the page. Huntress documented a campaign in which the address bar showed chatgpt.com while the content came from an attacker.

The campaign used Custom GPTs. A Custom GPT is a personalised version of ChatGPT that anyone can build, with their own instructions, files and tools. These pages sit on the genuine chatgpt.com site. Huntress identified two of them in this campaign. The second appeared after the first was removed.

The attackers titled one "Plus 5.6", so it could pass for a new ChatGPT model. Under the title, the page says it comes from a "community builder". Huntress notes that this is a tip-off only for people who already know what a Custom GPT is.

How victims reached it

In some incidents, victims searched Google for "chatgpt" and clicked a sponsored result. That link led to the Custom GPT page. Sponsored results appear ahead of ordinary listings. Huntress says this placement makes a visit more likely, as it has seen in other abuse of AI platforms.

The Custom GPT gave one answer to every prompt. It posted a "Service Availability Notice" and said the primary domain had limited availability. To continue, users had to upgrade to Plus or use a "backup domain".

That backup was a Google Sites page styled as a Cloudflare CAPTCHA check. It carried a ClickFix lure, a trick that tells users to copy a command and paste it into their own machine. The user, not the malware, runs the first step.

40
Incidents Huntress responded to (at least)
Source: Huntress, via Help Net Security (September 29, 2026)
2
Of those, confirmed via a Custom GPT
Source: Huntress, via Help Net Security (September 29, 2026)

The 40 incidents trace to the Google Sites domain, not to ChatGPT itself. Only two were confirmed to have come through a Custom GPT. These figures are what Huntress's own team saw, not a measure of total victims.

How the infection works

The pasted command runs PowerShell, which downloads a script. In the samples Huntress analysed, the attackers wrote the download server as one long integer, 1614733393. Windows converts it into an ordinary IP address. A rule or URL filter built to spot the familiar four-part format never sees one.

The script hides every telling string behind two layers of encoding. It then installs a package, ISOSimple.msi, silently. That package contains a genuine, Canon-signed program, COTFileReadApp.exe.

Windows looks in a program's own folder first when it needs a DLL, a shared code file. The attackers placed a patched copy of a Canon DLL beside the signed program. It loaded their code. This is called DLL sideloading. The running process carries a valid signature, so it looks trustworthy.

The next stage hides inside a file that claims to be audio. Common.Integrator.Preview.wav has a valid audio header. Part-way through, the audio turns into encrypted code. From there the chain reaches an encrypted archive, monitor.raw, holding a persistence script and the trojan.

8
Hops in this infection chain
Source: Huntress. Huntress says most ClickFix chains have two or three.

The trojan can run remote desktop sessions, capture the camera and microphone, search file contents across the host and launch further payloads. It finds its control server through DNS-over-HTTPS. Those lookups travel inside ordinary HTTPS traffic, so they do not appear in local DNS logs.

It also comes back. The script checks for its Run key every 150 seconds and its scheduled task every 875 seconds. Both are named Canon Configuration Reader. If one is deleted while the process runs, the script restores it. Huntress advises killing the process first, then removing both.

In one incident, Microsoft Defender quarantined the installer. By then it had already run, and the persistence carried on.

A replacement turned up within days of the takedown

Huntress reported the first Custom GPT to OpenAI. It was down by September 25. On September 27, Huntress found a replacement linked to the same campaign. The second version used a Stardock-signed program and a different hiding place for the loader, but the trojan was byte-for-byte the same.

Help Net Security checked the second page. It reports the page is still online but no longer points to the ClickFix lure. Huntress says the attackers are working on a new installer.

What this means for your organisation

The lesson here is that a familiar host is not proof of a trustworthy author. A victim in this chain saw a chatgpt.com address and a Cloudflare-branded check. In some incidents the path began with a sponsored search result. Advice limited to "check the domain" would not have flagged it.

The malware is elaborate, yet the attack depends on one human action. Help Net Security advises layered defence: train users, make the instructions hard to follow, and keep detection in place for when those steps fail. The paste step is the cheapest place to start.

Questions to put to your security team:

1. Can standard users open the Win+R Run dialog and PowerShell? Help Net Security cites restricting both as a way to make the instructions hard to follow.

2. Does awareness training say that no genuine website or CAPTCHA asks users to paste commands into a terminal?

3. Can we detect a Run key or scheduled task named Canon Configuration Reader, or a signed program loading an unsigned DLL from its own folder?

4. What is our policy on sponsored search results for AI tools, and do we offer staff a sanctioned link instead?

A trusted domain tells you where a page is hosted. It does not tell you who built it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Huntress.

Share this insight