THREAT actors are abusing ChatGPT Custom GPTs to deliver a multi-stage remote access tool (RAT), according to Huntress’ findings reported by Security Affairs. The campaign has been observed across at least 40 incidents, with two confirmed infections driven by Custom GPTs.
In the attack chain, a user searches for ChatGPT, lands on a page that imitates a genuine GPT on the real chatgpt[.]com domain, and is told the service is temporarily unavailable, directing them to a “backup domain” that hosts a fake Cloudflare CAPTCHA. From there a ClickFix lure prompts the user to copy a command into Windows Run, which executes a PowerShell one-liner to download and install an MSI payload.
Defender detections captured the role of PowerShell to msiexec in the chain; the initial MSI then leads to a multi-stage, heavily obfuscated infection sequence.
Technically, the core approach relies on DLL sideloading of a legitimate Canon binary (COTFileReadApp[.]exe) from Canon’s CaptureOnTouch, with a manipulated companion DLL (rdCore[.]dll) that hosts the malicious payload. The loader is delivered via a WAV file containing an encrypted loader, which then decrypts and loads a bespoke archive (monitor[.]raw) containing 315 folders and 806 files, plus a persistence script and the final RAT.
The final payload exfiltrates and grants extensive control, including remote desktop, screen/camera/audio capture, browser data access, file search, and execution of additional payloads in multiple formats. C2 communications leverage DNS-over-HTTPS through Cloudflare, Google, and Quad9 to blend with normal HTTPS traffic.
A later variant used a Stardock-signed binary and a Microsoft NuGet package instead of the Canon distribution, with a similar load/persistence/RAT sequence and the removal of the Mark-of-the-Web tag to bypass SmartScreen prompts. OpenAI acted by removing the implicated Custom GPTs on 25 September 2026.
Researchers advise monitoring for PowerShell invoking msiexec against GUID-named MSI in temp, canonical or Stardock binaries running from fake AppData folders, and Run keys or scheduled tasks reappearing after deletion. They emphasise that detections tied to Canon or Stardock names may miss subsequent swaps, underscoring the need for detection to focus on the whole eight-stage pattern rather than fixed filenames.