THREAT actors have been abusing ChatGPT Custom GPTs to masquerade as legitimate product offerings, directing users to malicious sites that deploy ClickFix lures to drop malware. Huntress observed the activity in late September 2026, marking another abuse of AI platform features to facilitate crime. Victims interact with an attacker‑created Custom GPT that replies with a Google Sites link, which leads to a ClickFix‑style attack, culminating in the download and execution of a malicious MSI installer.
The MSI installer triggers a DLL sideloading chain to load a rogue DLL, which in turn loads an encrypted loader from a WAV audio file. The loader unpacks a trojan and a persistence script, bypasses AMSI, unhooks ntdll[.]dll to evade user‑mode monitoring, and runs anti‑virtual machine checks.
The final payload is a remote access trojan (RAT) with a broad feature set: it inventories antivirus status, launches remote desktop and screen broadcasts, captures camera, microphone and system audio, identifies browsers, and can drop and run secondary payloads and scripts. DNS‑over‑HTTPS is used to reach the C2 server, with lookups hidden in normal HTTPS traffic to avoid local DNS logging.
Around 40 users were reported affected in this campaign, with initial exposure stemming from sponsored Google search results for “chatgpt.” The campaign aligns with a wider trend of attackers using trusted online services (including Google Sites) and AI‑driven tools to deliver malware. Huntress emphasises that threat actors continue to turn trusted platforms into social‑engineering entry points for invasive payloads.