Cybersecurity researchers at Huntress have uncovered a campaign where hackers built a custom ChatGPT model to trick people into launching malware on their own PCs, turning one of OpenAI’s own features against its users.
The campaign starts on Google search. Anyone searching for “chatgpt” might click a sponsored ad at the top of the results page, which redirects to a custom GPT named “Plus 5.6” hosted on the official ChatGPT domain. Because the link sits on OpenAI’s actual site, most people reasonably assume it’s safe.
Fake error messages and a ClickFix trap
Once a user starts chatting with the bot, it displays a fake “Service Availability Notice,” claiming the primary servers are overloaded and suggesting a backup link hosted on Google Sites instead. That backup page then presents a fake Cloudflare check, triggering a classic ClickFix social engineering tactic that asks the user to copy a line of code and paste it into a PowerShell terminal. Once executed, that command silently downloads an installer named ISOSimple.msi into a temporary folder to begin setting up the malware.

Disguised files and a persistence mechanism
To avoid tripping antivirus software, the attackers used legitimate software files to side-load their code. In earlier versions of the campaign, they used a signed Canon app (COTFileReadApp.exe) and hid the malicious payload inside what looked like a harmless .WAV audio file. Later, they switched to a Stardock executable and hid the code inside a Microsoft NuGet package instead.
Once the full payload lands, it deploys a Remote Access Trojan (RAT), giving attackers remote desktop access, camera and microphone capture, and full control over files on the infected machine. According to BleepingComputer, the malware also creates a new Windows Registry key and a scheduled task named “Canon Configuration Reader” so it relaunches every time the system reboots.
Huntress tracked more than 40 incidents connected to the Google Sites page used in the campaign, and confirmed that at least two tied directly back to custom GPTs. OpenAI pulled the initial malicious model on September 25, though researchers found a second active variant just two days later. The timing stands out given that OpenAI is scheduled to retire custom GPTs on December 11, suggesting the attackers are trying to squeeze as much use out of the feature as they can before it disappears.

Google Pixel Watch 5 (45mm)
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.









Comments & Discussions
Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.