As reported by The Hacker News, Huntress disclosed a campaign in late September 2026 in which threat actors weaponized ChatGPT Custom GPTs to distribute a remote access trojan through ClickFix-style social engineering. This is not a vulnerability in OpenAI's infrastructure — it is something arguably harder to patch: the abuse of trust and feature surface.
Why This Campaign Is Structurally Significant
The attack chain reported by Huntress is technically unsophisticated, but that is precisely the point. The operators did not need to compromise OpenAI. They simply created Custom GPTs — a feature OpenAI offers openly — and programmed them to respond to user prompts with a Google Sites link dressed up as a service availability notice. From there, a fake Cloudflare CAPTCHA presented a PowerShell snippet for the victim to copy and execute, which deployed an MSI installer leveraging DLL sideloading via a legitimate Canon-signed binary, with the final payload extracted from a .WAV file.
The real vulnerability here is not a CVE — it is the implicit trust users place in content hosted on a platform ending in chatgpt.com.
This campaign follows a documented pattern of AI platform feature abuse. We have already seen shared AI chatbot conversations and Claude Artifacts used as malware delivery vehicles. Custom GPTs are simply the latest feature surface to be repurposed. The common thread is that AI providers are shipping collaborative and sharing features faster than they can implement content provenance, creator vetting, or outbound-link sanitization.
The Trust Proximity Problem
What makes this particularly effective is what we at Shield53 call trust proximity. Users have been trained to be suspicious of random domains. They have not been trained to be suspicious of a Custom GPT hosted on the official ChatGPT platform, especially when a Google sponsored ad for a search like "chatgpt" funnels them there. The chatgpt[.]com domain lends the attack an aura of legitimacy that a standalone phishing site can never achieve.
Who Is at Risk
Shield53 Recommendations
Immediate Actions
- Block and hunt: Add indicators for the documented Custom GPT URLs and the MSI filename "ISOSimple.msi" to your endpoint and email gateways
- Detect the sideload chain: Create EDR/SIEM rules for
COTFileReadApp.exeexecuting from non-standard directories and loadingceiinfolog.dllorrdCore.dll - Alert on PowerShell + clipboard: The ClickFix technique relies on the user running pasted PowerShell. Alert on PowerShell execution originating from clipboard content or browser processes
- Review Google traffic: The chain uses Google Sites for the intermediary step. Consider whether your organization's URL filtering policy should treat newly created Google Sites domains with heightened scrutiny
Strategic Actions
- AI acceptable use policy: If you have not already, establish and enforce a policy on which AI tools and features are approved for business use — and communicate the Custom GPT risk to employees now
- Search ad awareness: Train users that sponsored Google results for AI tools are a known attack vector. Bookmark legitimate destinations instead of clicking ads
- Egress filtering: Ensure DNS filtering covers newly-registered domains and free hosting platforms that attackers use as intermediary infrastructure
The broader implication is clear: every AI platform that ships a sharing, marketplace, or customization feature is creating a new attack surface that inherits the platform's trust reputation without inheriting its security controls. Until providers like OpenAI implement creator verification, outbound link analysis, and rapid takedown for malicious Custom GPTs, defenders must treat AI platform-hosted content with the same skepticism as any other user-generated content on the internet.