A fake ChatGPT model on chatgpt.com delivered a RAT
A Custom GPT called Plus 5.6, pushed by Google ads, sent users to a fake CAPTCHA that installed a camera-capable RAT. How the chain works and how to hunt it.
By Yaali. October 5, 2026, 6 min read, Phishing, Threat intel, Windows.
Huntress has published a campaign, seen in late September 2026, that starts on chatgpt.com itself. A sponsored Google result for "chatgpt" led to a Custom GPT named "Plus 5.6", built to pass for a real model. Whatever the visitor typed, it answered with a "Service Availability Notice" saying the primary domain had limited availability and pointing to a "backup domain". That backup was a Google Sites page with a fake Cloudflare CAPTCHA that asked the visitor to paste a PowerShell command, the trick known as ClickFix.
The command starts an eight-stage chain that ends in a remote access trojan (RAT) able to run remote desktop sessions and record the camera, microphone and system audio. Huntress responded to at least 40 incidents tied to the Google Sites page and confirmed two that came through the Custom GPT. OpenAI removed the first GPT on September 25; a second one with the same name was found on September 27. Any Windows user who searches for ChatGPT instead of typing the address is in the target group, and every page up to the PowerShell prompt sat on a domain most web filters trust.

How it works
A Custom GPT is a configured ChatGPT assistant that users can build and share under chatgpt.com/g/. The creator writes the instructions, so a GPT can be told to ignore the question and print a fixed message. Here the message mimicked a service notice, which reads as plausible because it appears inside the real ChatGPT interface, behind a real certificate and the right address bar.
The Google Sites page did the rest. ClickFix pages show a fake verification check, put a command on the clipboard when the visitor clicks, then tell them to open a prompt, paste and press Enter. The user runs the command with their own rights, so there is no download for the browser to warn about. In the samples Huntress analysed, the command fetched its next script from a host written as a decimal number, 1614733393, which Windows resolves to 96.62.224.81. A URL filter or detection rule looking for a dotted IP address never sees one.
That script installs an MSI package silently. The first variant, ISOSimple.msi, presents itself as "Advanced Printer Configuration Reader" from a publisher called Softplicity, installs to %LOCALAPPDATA%\Programs\Advanced Printer Configuration Reader\, and sets ARPSYSTEMCOMPONENT=1 so it does not appear in Programs and Features.
The package carries a genuine, signed Canon program, COTFileReadApp.exe, next to a patched copy of its logging library ceiinfolog.dll. Windows loads a program's DLLs from its own folder first, so the signed program loads the attacker's DLL (DLL sideloading). The patched DLL pulls in rdCore.dll, which extracts a loader hidden inside a WAV file in the installer. The second wave swapped the Canon pair for Stardock's signed DeElevate64.exe with a patched DeElevator64.dll, and hid the loader in a Microsoft NuGet package instead of audio.
The loader is position-independent shellcode that works to blind defences before it does anything else. It patches the Antimalware Scan Interface (AMSI) in amsi.dll, the hook Microsoft Defender and other products use to inspect scripts in memory. It maps a fresh copy of ntdll.dll to step around the hooks endpoint detection and response (EDR) tools place in the loaded one. It also checks CPU vendor strings and drivers for VMware, VirtualBox, Hyper-V, QEMU, Xen and Parallels, so it stops in a sandbox. It then opens monitor.raw, an encrypted custom archive of 315 folders and 806 files that holds a persistence script and the RAT itself.
What the RAT does
Persistence is written to survive cleanup. A Run value under HKCU and a scheduled task, both named "Canon Configuration Reader" in the first variant, are rebuilt if removed: the Run key is checked every 150 seconds, the task every 875 seconds, and the key is written again at every Windows shutdown. Deleting one of them by hand while the malware runs does nothing.

The RAT covers remote desktop and screen broadcast, camera, microphone and system audio capture, and a file manager that searches file contents across the whole machine. It knows 17 browsers, from Chrome and Edge to Yandex and Arc, and can drop and run follow-on payloads in nine formats, including EXE, DLL, MSI, PowerShell and ZIP. It fingerprints the host, including installed antivirus and Defender status. For command and control (C2), it resolves names through DNS-over-HTTPS (DoH) to Cloudflare, Google and Quad9, so its lookups travel as ordinary HTTPS to well-known resolvers and never show up in your internal DNS logs. Huntress did not find the C2 address in the recovered files.
In one incident the RAT dropped a legitimately signed GOMCam2024.exe into %LOCALAPPDATA%\AppstorageFile\, which launched chrome.exe with a throwaway profile under %TEMP%.
What to do
There is no patch to apply: every step abuses a legitimate service or a signed program. The work is blocking, hunting and cleaning up.
- Block the known infrastructure: 96.62.224.81 at the firewall and proxy (and the decimal form 1614733393 if your proxy matches on host strings), and the page
sites.google.com/view/antibot172881. Expect new addresses; these only stop this wave. - Hunt for the chain. In EDR or Sysmon process events (Sysmon event ID 1), look for
powershell.exespawningmsiexec.exeto install a GUID-named MSI from%TEMP%, and forCOTFileReadApp.exeorDeElevate64.exestarted bymsiexec.exefrom under%LOCALAPPDATA%\Programs\. Neither program has any reason to run there. - Check persistence on every Windows host:
reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Runandschtasks /query /fo LIST /vfor "Canon Configuration Reader" or any value or task pointing into%LOCALAPPDATA%\Programs\. Look for unsignedceiinfolog.dllorrdCore.dllnext to the Canon program, and forGOMCam2024.exein%LOCALAPPDATA%\AppstorageFile\. - If you find it, isolate the machine first. The watchdog rebuilds the Run key and task within minutes, so reimage rather than delete entries by hand.
- Treat everything the user had open as exposed. Reset passwords saved in any browser on that machine, revoke active sessions and tokens for their cloud and SaaS accounts, and assume the camera and microphone were live while it ran.
Huntress warns that rules keyed to the Canon or Stardock names will miss the next swap, which the second wave already proved. Write detections on behaviour: PowerShell launching a silent MSI from a temp folder, signed programs started by msiexec.exe from fake product folders, and persistence that comes back after deletion.
Trusted domains are now part of the lure
Every stop before the PowerShell prompt was on google.com, chatgpt.com or sites.google.com, so category and reputation filtering waved it through. Tell users that ChatGPT never moves to a "backup domain", that they should open it from a bookmark rather than a search ad, and that no CAPTCHA ever asks them to run a command. If your organisation uses ChatGPT Enterprise or Edu, the GPTs tab of the admin panel controls whether members can use GPTs built outside your workspace; that helps only while staff are signed in to the company workspace, which this lure did not rely on. Where staff do not need PowerShell, remove it with AppLocker or App Control for Business.
We test whether endpoints catch chains like this one in our safeguarding and hardening work and hunt for them in security operations. If you want someone to check your Windows fleet for these indicators, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Huntress, The Hacker News, Security Affairs, IT Security Guru, BleepingComputer, SecurityWeek, Help Net Security, OpenAI Help Center.
Read next
- Antino backdoor hides its command channel in Microsoft 365
- Star Blizzard's RedFlick: fake invites, one-click backdoor
- A ShinyHunters arrest: what it changes for defenders
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.