"Instead of one encrypted blob, it's a custom archive with its own folder tree, basically a homemade, encrypted zip file," Huntress researchers said.
Huntress investigation and timeline
Managed detection and response firm Huntress uncovered a campaign in which custom variants of OpenAI’s ChatGPT were used to steer victims into a ClickFix-style lure that ultimately delivered a remote access trojan (RAT). Huntress says it investigated at least 40 incidents that connected to the attacker-controlled Google Sites page; only two of those incidents involved a custom GPT variant. OpenAI removed the first malicious GPT by September 25, and Huntress discovered a second GPT linked to the same campaign on September 27 that remained active when the researchers published their report.
How attackers weaponized custom GPTs and Google Sites
The threat actor abused a legitimate OpenAI feature that lets users create and publish custom GPTs — tailored ChatGPT instances that combine instructions, extra knowledge, and skills — to distribute malicious guidance. The actor published a model named "Plus 5.6" and configured it to direct users to an alleged backup site hosted on Google Sites. That page presented a fake Cloudflare check and instructed visitors to run a PowerShell command; executing that command began the multi-stage infection chain Huntress observed.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadClickFix ruse and the multi-stage infection chain
Huntress linked the campaign to ClickFix-style social engineering previously seen in deceptive ChatGPT conversations, but using published custom GPTs represents a novel delivery vector. If a user ran the supplied PowerShell, it installed a malicious MSI that launched a legitimate, signed host application alongside a modified DLL that loaded the malware. The operators changed the host over time — Huntress observed a switch from a Canon-signed host application to a Stardock-signed one — and altered how the loader was concealed and delivered, while retaining the same RAT payload.
Huntress flagged a particularly notable step in the chain (phase 6): the attackers built a custom encrypted file system to conceal the persistence script and the RAT. Rather than a single encrypted blob, the archive used by the attackers begins with a small header, followed by an index of 1,128 entries (one per file or folder, each recording its parent, its size and a per-file key), then the file contents packed back to back — essentially a homemade, encrypted zip file.
RAT capabilities and persistence mechanics
The deployed payload is a remote access trojan with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and executing additional payloads. For persistence the malware creates both a new Run key in the Windows Registry and a scheduled task, with both persistence mechanisms named "Canon Configuration Reader." Huntress also observed that most of the infection chain runs in memory or is supported by files that appear benign, complicating detection.
Detection opportunities for technologists, enterprises, and end users
- Technologists and security teams: Huntress recommends process-activity monitoring as the primary detection vector because much of the chain runs in memory or uses benign-looking files. Specific signs include PowerShell activity that invokes msiexec.exe to silently launch an MSI installer from the temporary folder.
- Enterprises and procurement leaders: Huntress points to a signed application starting from an unusual folder under %LOCALAPPDATA%\\Programs\\ as an indicator, and warns that the Run value and scheduled task tied to "Canon Configuration Reader" will reappear if deleted — a repeatable sign of compromise to watch for in remediation.
- End users and the general public: The campaign demonstrates that malicious instructions can be hosted on legitimate domains, including ChatGPT.com and Google Sites; in this case, a fake Cloudflare check on the Google Sites page was used to trick visitors into running a PowerShell command that launched the attack.
OpenAI hosts custom GPTs and has said it plans to retire the custom GPT feature on December 11. Huntress's takedowns and observations — the removal of the first GPT on September 25 and the discovery of a second on September 27 — underscore that publishing on a legitimate platform can lend malicious guidance extra credibility. The report hands defenders concrete indicators and a clear phase of the chain to inspect: the bespoke encrypted archive with 1,128 indexed entries and the PowerShell-to-msiexec step that drops the signed host and modified DLL.
The immediate facts are simple and stark: attackers used a hosted custom-GPT listing named "Plus 5.6" to send victims to a Google Sites page that displayed a fake Cloudflare check and pushed a PowerShell command that installed a RAT with remote-control and surveillance capabilities, persisting under the name "Canon Configuration Reader." Whether the planned retirement of custom GPTs on December 11 will close this particular avenue of abuse — or merely push operators to new legitimate-looking distribution points — remains the central operational question left for defenders and platform operators to answer.




