No less than 40 users have been infected as part of a campaign that weaponizes ChatGPT Custom GPT pages and Google Sites to deliver a multi-stage remote access trojan (RAT), Huntress reported in late September 2026.
How attackers used ChatGPT Custom GPTs as the entry point
Huntress says the operation began with a sponsored search result for terms such as "chatgpt" on Google that promoted attacker-created Custom GPT pages hosted on the legitimate ChatGPT site. The two observed Custom GPT links are listed in Huntress's report as:
- chatgpt[.]com/g/g-6ab595ad6554819181b686d4876efb80-plus-5-6
- chatgpt[.]com/g/g-6ab6ba039440819185ed491740b11cf8-plus-5-6
Users who interacted with the Custom GPT named "Plus 5.6" received a "Service Availability Notice" instructing them either to upgrade their subscription tier or to follow a backup Google Sites link because of "limited availability on the primary domain." The notice explicitly displayed: "We recommend using the backup domain if you need immediate access." That backup link led to a Google Sites page that staged a fake Cloudflare CAPTCHA as a ClickFix-style lure.
ClickFix lure to PowerShell to MSI to DLL sideload
Huntress describes a classic ClickFix flow: the fake CAPTCHA coerces victims into copying and executing a malicious PowerShell command. That command deploys an MSI installer named "ISOSimple.msi." The MSI abuses a legitimate Canon-signed binary, COTFileReadApp.exe, to sideload a modified Canon DLL (ceiinfolog.dll) that in turn loads an unsigned secondary DLL (rdCore.dll).
According to Huntress, the altered Canon DLL contains code to extract an encrypted loader from an audio file named "Common.Integrator.Preview.wav." The loader's shellcode then unpacks the trojan and a persistence script from an encrypted filesystem ("monitor.raw") after performing multiple anti-detection steps.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageAdvanced evasion and RAT capabilities
Huntress documents several anti-analysis techniques: bypassing AMSI, unhooking ntdll.dll to evade user-mode monitoring, and performing anti-virtual-machine checks by comparing CPU vendor strings against VMware, VirtualBox, Hyper-V, QEMU, Xen, and Parallels drivers and services. To find its command-and-control server (the strings call it the "Gate"), the RAT uses DNS-over-HTTPS through Cloudflare, Google, and Quad9 so lookups travel inside ordinary HTTPS traffic and "never appear in local DNS logs," Huntress said.
The RAT itself supports a broad feature set. Huntress reports it can:
- Document installed antivirus and Microsoft Defender status and enumerate the system profile
- Run remote desktop sessions and screen "broadcasts"
- Capture camera input, microphone, and system audio
- Recognize 17 web browsers and launch the default browser
- Search file contents using a built-in file manager
- Drop and run secondary payloads (.EXE, .DLL, .MSI) and scripts (PowerShell, batch, VBScript, JavaScript)
Huntress also observed the malware dropping a signed binary named "GOMCam2024.exe" that launches Google Chrome with a disposable browser profile in the "%TEMP%" directory.
Related ClickFix campaigns and secondary chains
Huntress placed this activity alongside multiple ClickFix-oriented campaigns seen in the wild. Examples in the report include Google Sites phishing pages that mimic OpenAI Codex and Anthropic Claude to push stealer malware in-memory; a compromised site using "EtherHiding" to load JavaScript that serves a ClearFake reCAPTCHA and ultimately drops Amatera Stealer; malvertising and phishing that stage fake Cloudflare interstitials on bulletproof hosting to deliver trojanized installers; and a ClickFix cluster active since at least November 2025 that used 31 compromised business websites to deliver droppers and PowerShell-based C2 agents tied to Polygon-based EtherHiding.
GuidePoint Security warned that the initial remote-access backdoor observed in these chains "has since been observed delivering a real-time banking trojan capable of intercepting login credentials and two-factor codes from major banks and cryptocurrency exchanges as victims type them."
Huntress noted some of these ClickFix and ClearFake campaigns targeted Ukrainian government systems and that one cluster is tracked as UAT-10820.
What this means for security teams, procurement leaders, and end users
Security teams should watch for execution chains that begin with browser-driven social-engineering lures served from legitimate platforms — in this report, ChatGPT Custom GPT pages and Google Sites — and look for telltale artifacts such as ISOSimple.msi, COTFileReadApp.exe sideload activity, the modified Canon DLL names (ceiinfolog.dll, rdCore.dll), Common.Integrator.Preview.wav, monitor.raw, and the dropped GOMCam2024.exe launching Chrome from %TEMP%.
Procurement and platform owners who manage search ad buys or hosted application listings should note that a sponsored search result was the starting point; ad placements and Custom GPT pages can be abused to create credible trust signals for victims.
End users confronted with unexpected installation prompts, Cloudflare-style CAPTCHAs that ask them to paste and run a PowerShell command, or "Service Availability" messages urging a backup domain should treat those prompts as suspicious and avoid executing commands or installers supplied from such pages.
Huntress summed up the pattern plainly: "Overall, threat actors continue to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT's Custom GPT feature or through Google Sites for hosting a ClickFix attack."




