Attackers abused ChatGPT Custom GPT pages branded as “Plus 5.6” and promoted them through sponsored Google Search results to impersonate a legitimate ChatGPT model. Victims were redirected to a fake backup domain hosting a Google Sites page styled as ChatGPT and Cloudflare verification prompts; the ClickFix lure instructed them to run PowerShell, silently installing a malicious MSI and a sophisticated remote-access trojan (RAT). Huntress handled at least 40 incidents tied to the Google Sites domain, including two confirmed infections originating from Custom GPT lures, and observed replacement lures after the original was removed.
The campaign used signed third-party software for DLL sideloading and layered persistence. An initial variant abused Canon-signed CaptureOnTouch components, concealed its loader in a WAV file, and created Run-key and scheduled-task persistence labeled “Canon Configuration Reader.” A second variant preserved the RAT framework but used Stardock-signed DeElevate64.exe, a modified DeElevator64.dll, and a NuGet package carrier, establishing persistence as “Stardock DeElevation Tool.” Organizations should treat sponsored AI-tool search results and browser verification prompts that require shell commands as high-risk social-engineering activity.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Huntress identified a replacement malicious Custom GPT connected to the same RAT-delivery campaign after the initial lure was removed.
Huntress notified OpenAI about the first observed malicious “Plus 5.6” Custom GPT, after which that Custom GPT was taken down.
The delivery server hosted UltraFreeISOCreateWizardSolution.msi, indicating that the operators may have rotated signed application components and installer disguises used in the campaign.
Threat actors used sponsored Google Search results to direct victims to ChatGPT Custom GPTs impersonating legitimate models, which redirected to a Google Sites ClickFix page. The lure executed a PowerShell stager that installed MSI payloads and deployed a RAT using Canon- or Stardock-signed binaries for DLL sideloading and redundant Run-key and scheduled-task persistence.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.