A malvertising campaign spotted in late September used a malicious Custom GPT hosted on chatgpt.com to deliver a remote access trojan. According to Huntress researchers, the GPT named "Plus 5.6" was promoted through sponsored Google results for users searching for "chatgpt." When victims tried to use it, the GPT claimed the service was unavailable and pointed them to a Google Sites page presenting a fake Cloudflare CAPTCHA.
The page used a ClickFix attack, instructing users to copy and paste a command into their terminal. Running it triggered a chain that sideloaded a full-featured RAT through legitimately signed Canon executables, and later Stardock executables. Huntress said it responded to at least 40 incidents from the Google Sites domain, with two confirmed to have come through a Custom GPT instance.
OpenAI removed the first malicious GPT after researchers reported it, but the attackers quickly created another one. That second instance was still online at the time of writing, though it no longer pointed to the malicious lure. The researchers noted these campaigns often stay live for only hours or days. They advise users to treat any page that asks them to paste a command into a Run dialog, Terminal, or PowerShell as an attack, and to be cautious with sponsored search results. For organizations, they recommend layered defenses, including user training and restricting execution tools.