A malicious Custom GPT called “Plus 5.6” used ChatGPT’s real website as the first step in a malware lure. Some users reached it through sponsored Google results; the GPT then directed them to a Google Sites “backup” page, where a fake Cloudflare verification prompt urged them to run a PowerShell command. The command—not ChatGPT itself—started the infection.
1
2
13
How the ClickFix lure worked
The attackers presented “Plus 5.6” as though it were a ChatGPT offering. When users interacted with the Custom GPT, it pointed them to a supposed backup page. That page used a fake CAPTCHA-style check to persuade visitors to copy and run a command on their own computers—a social-engineering tactic known as ClickFix.
1
2
11
The use of trusted-looking services was part of the deception: a sponsored search result, a page on ChatGPT’s genuine site and a Google Sites page could all appear familiar. None of those details made the command safe to run.
1
2
From PowerShell to a remote-access trojan
The PowerShell command launched an obfuscated script that downloaded and ran a malicious MSI installer. The installer then used DLL sideloading: it loaded a malicious DLL through a legitimate, signed Canon executable. This let the attackers use a trusted program as part of the next infection stage.
5
8
Huntress’s reporting also describes persistence through a Windows Run key named “Canon Configuration Reader.” The mechanism checked for the key and restored it if it was missing, helping the malware run again after interruption or restart.
5
The final payload was a remote-access trojan (RAT). Reporting on the campaign describes capabilities including remote desktop access, screen viewing, audio and camera capture, file searches, host reconnaissance and the ability to run additional payloads.
8
A technical summary says the RAT communicated with attacker-controlled command-and-control infrastructure using DNS-over-HTTPS, with Cloudflare, Google and Quad9 resolvers named in the report.
14
What the incident count does—and doesn’t—show
Huntress said its security operations center responded to at least 40 incidents associated with the specific Google Sites domain. That figure does not mean all 40 incidents were traced to the Custom GPT: Huntress confirmed that two came through a Custom GPT instance.
1
13
After the first malicious GPT was removed, another linked to the campaign appeared. This illustrates why taking down one lure does not necessarily end a campaign: attackers can create a replacement and continue directing people to the same kind of malicious page.
4
9
How users and organizations can reduce risk
- Don’t run commands to pass a CAPTCHA. A website’s request to paste text into PowerShell, Terminal or another command interface is a serious warning sign.
- Check the destination, not just the search result. A sponsored listing or a page hosted on a familiar service does not establish that a link or instruction is legitimate.
- For organizations, train staff on ClickFix tactics and restrict script execution where it is not needed. Monitor for unexpected PowerShell activity followed by MSI installation or suspicious DLL loading.
1
5
- If someone has already run the command, treat the device as potentially compromised. Contact the organization’s security or IT team promptly so it can investigate the device and determine whether accounts or other systems may be at risk.
The core lesson is that attackers used trusted interfaces to build confidence, but relied on the victim to execute the command. A genuine platform can host a deceptive lure; a CAPTCHA should never require you to run a script on your computer.