A SecurityWeek report from 29 September 2026 details a ClickFix campaign that abuses personalised ChatGPT Custom GPTs to impersonate legitimate products and lure users into running malicious PowerShell commands. Attackers created two Custom GPTs that respond to prompts with a Google Sites link to a ClickFix page. On that page, victims were prompted to execute a PowerShell command that downloaded a malicious MSI as part of a multi-stage infection.
OpenAI removed the offending Custom GPTs on 25 September, but a second instance was discovered on 27 September. In all, Huntress estimates at least 40 users were compromised, with two incidents directly tied to a Custom GPT instance.
The campaign relied on social engineering and search results; victims reached the Custom GPT via a sponsored Google search for ChatGPT, where the page appeared at the top of results. The attackers named the GPT “Plus 5.6” and claimed it was from a “community builder,” presenting a fake notice about limited availability and urging an upgrade or use of a backup domain. The page was hosted on Google Sites and triggered a Cloudflare CAPTCHA step as part of the attack.
The initial payload abused a Canon-signed DLL sideloading technique to achieve persistence via a User Run key and a scheduled task masquerading as “Canon Configuration Reader.” A loader, disguised as an audio file, then conducted checks before loading an obfuscated package containing the final payload, a RAT capable of fetching and executing further payloads and communicating with a C2 server over DNS-over-HTTPS via Cloudflare, Google, and Quad9. The operators later switched to a Stardock executable and a patched DLL delivered through a NuGet package rather than an audio file.