Malicious Custom GPTs on ChatGPT.com Lure Users into Installing Remote Access Trojans

A new scam uses sponsored Google ads to direct users to malicious Custom GPTs on the legitimate chatgpt.com domain. These fake interfaces display a 'Service Availability Notice' and link to a Google Sites page mimicking a Cloudflare check. The page instructs users to run PowerShell commands, installing a remote access trojan (RAT) via signed applications. Huntress confirmed at least 40 incidents, with OpenAI removing the first instance by September 25, 2026. Experts warn that trusted domains like ChatGPT and Google are being abused to bypass security awareness, urging users to never paste commands into terminals as a verification step.
Key points
- Attackers created Custom GPTs named 'Plus 5.6' on the official chatgpt.com domain, promoted via sponsored Google Search results for 'ChatGPT'.
- The malicious interface displays a fake 'Service Availability Notice' and directs users to a Google Sites page posing as a Cloudflare CAPTCHA check.
- The lure instructs victims to copy and paste a PowerShell command, which installs a remote access trojan (RAT) using legitimately signed Canon or Stardock executables.
- Huntress reported at least 40 incidents linked to the campaign, with OpenAI removing the first malicious GPT on September 25, 2026, and a second variant appearing on September 27, 2026.
- The RAT enables remote desktop access, camera/microphone capture, file searches, and network reconnaissance, with persistence mechanisms named 'Canon Configuration Reader' in the Windows Registry.
Background
This incident follows a broader trend of 'ClickFix' attacks where social engineering tricks users into executing malicious commands. In August 2026, a similar scam hijacked Chrome extensions to deliver malware, highlighting the growing reliance on trusted brand names to lower user suspicion. OpenAI is also planning to retire the Custom GPT feature on December 11, 2026, which may reduce this specific attack vector in the future.
How outlets are covering it
ZDNET emphasizes the deceptive nature of the sponsored Google links and advises users to type chatgpt.com directly into browsers to avoid ads. Help Net Security and Dark Reading focus on the technical complexity of the attack, noting that Huntress researchers identified the use of signed applications (Canon, Stardock) to sideload malware and the custom encrypted file system used to conceal the RAT. BleepingComputer highlights the novelty of abusing the Custom GPT feature and notes that while OpenAI removed the first instance, a second variant remained active at the time of reporting. All sources agree that the use of trusted domains (ChatGPT, Google, Cloudflare) makes the scam particularly convincing, but they differ in emphasis: ZDNET targets end-user behavior, while the security firms focus on detection opportunities and organizational defense strategies.
Why it matters
This campaign demonstrates how threat actors are leveraging trusted AI platforms and search engines to bypass traditional security measures. By hosting malicious content on the legitimate chatgpt.com domain, attackers exploit user trust in the brand, making it harder for victims to distinguish between authentic services and scams. The use of ClickFix techniques, where users are tricked into executing commands themselves, complicates detection and response. As AI tools become more integrated into daily workflows, such attacks could lead to widespread data theft, espionage, and network compromise if users do not adopt stricter verification habits.
What to watch
OpenAI is expected to continue removing malicious Custom GPTs as they are identified, though the feature's retirement in December 2026 may limit long-term exposure. Security firms like Huntress are likely to update detection rules to flag PowerShell commands launching MSI installers from temporary folders or unusual program directories. Users should remain vigilant, avoiding sponsored search results for critical services and never executing commands prompted by web pages claiming to be verification tools. Organizations should reinforce training that no legitimate service requires users to paste commands into terminals for verification.
- This new ChatGPT scam tricks you into installing malware – how to spot the trap ZDNET
- Malicious Custom GPT on chatgpt.com lures users into installing a RAT Help Net Security
- Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure Dark Reading
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware BleepingComputer
- A fake ChatGPT sneaks into Google and can take control of your computer: Here’s how the scam works Diario AS
Want the full story? Read the original reporting
Read on ZDNET