As reported by BleepingComputer, Huntress has uncovered a campaign that weaponizes OpenAI's custom GPT feature to deliver remote access trojans through ClickFix-style social engineering. While the technical mechanics — PowerShell execution, MSI deployment, DLL sideloading — are individually well-understood, the novel element here is the trust chain abuse: an AI assistant hosted on chatgpt.com, surfaced through sponsored Google results, redirecting to a Google Sites page dressed up as a Cloudflare verification. Every layer borrows legitimacy from a recognizable brand.

Threat Alert: ClickFix attacks — where users are tricked into running clipboard-delivered PowerShell under the guise of a CAPTCHA or verification step — have been gaining traction throughout 2025 and 2026.

Why This Campaign Is Different

ClickFix attacks — where users are tricked into running clipboard-delivered PowerShell under the guise of a CAPTCHA or verification step — have been gaining traction throughout 2025 and 2026. What elevates this particular variant is the multi-stage trust exploitation:

Why This Campaign Is Different
Platform legitimacy: The malicious instructions originate from a custom GPT hosted on chatgpt.com, a domain users inherently trust. Security awareness training rarely conditions users to be suspicious of content served from a major AI provider's own infrastructure.
Search amplification: Sponsored Google results for the custom GPT increase reach beyond organic discovery, potentially catching users searching for AI productivity tools.
Infrastructure blending: The use of Google Sites for the redirect landing page adds another layer of platform-derived trust before the victim ever executes code.

The attack chain itself is a competent piece of tradecraft. The threat actor employs DLL sideloading using legitimately signed host applications — initially Canon-signed, then pivoting to Stardock-signed binaries — to bypass application allow-listing and signature-based detection. The persistence mechanism, combining a Run registry key and scheduled task both named 'Canon Configuration Reader,' is designed to blend into typical enterprise endpoint noise. Huntress also notes a custom encrypted archive structure concealing the RAT and persistence script, which frustrates static analysis and automated extraction.

The core issue isn't a vulnerability in OpenAI's platform — it's that any platform offering user-generated content creation at scale becomes an attack surface. Custom GPTs are effectively community-contributed code with social engineering potential.

Who Is at Risk

While Huntress observed roughly 40 incidents with only two confirmed custom GPT variants, the exposure profile is broader than the numbers suggest. The primary risk targets:

  • Non-technical knowledge workers who interact with AI assistants as part of daily workflows and may follow verification prompts without scrutiny
  • SMB environments where endpoint detection capabilities may be limited and PowerShell execution is not tightly controlled
  • Organizations without application allow-listing — the signed binary DLL sideloading technique is specifically effective against environments that trust code signing without deeper behavioral monitoring
The RAT payload is full-featured: remote desktop, audio and camera capture, file discovery, host reconnaissance, and secondary payload delivery. In an enterprise context, this represents potential for data exfiltration, lateral movement staging, and precursor activity for ransomware deployment.

Shield53 Recommendations

Immediate Actions:

  • Restrict PowerShell for non-administrative users using Constrained Language Mode and disable interactive PowerShell execution where not operationally required
  • Deploy behavioral EDR rules flagging signed binaries loading DLLs from user-writable locations — this is a hallmark of sideloading campaigns
  • Monitor for the persistence indicators: Run keys or scheduled tasks named 'Canon Configuration Reader' or similar legacy-software-mimicking names
  • Block or alert on outbound connections from Google Sites domains when initiated from PowerShell or MSI installer processes, which is anomalous for legitimate software installation flows
  • Detection rule for MSI-spawned processes: alert when msiexec.exe spawns child processes that load unsigned DLLs from temporary or user-profile paths

Strategic Actions:

  • Update security awareness training to explicitly address AI platform abuse — users should understand that content hosted on chatgpt.com or any AI assistant platform is not inherently safe to execute locally
  • Implement allow-listing for custom GPTs at the organizational level if your team uses ChatGPT enterprise or team plans — restrict to vetted, internally-created GPTs only
  • Hunt for lateral movement indicators if any endpoint has connected to Google Sites pages from a PowerShell execution context in the past 30 days
  • Review DLL sideloading defenses: ensure your EDR solution has capability-based或 code signing certificate reputation analysis rather than trusting any valid signature blindly

OpenAI's decision to retire custom GPTs on December 11 will close this particular attack vector, but the underlying pattern — abusing trusted platforms for social engineering distribution — will migrate to whatever replaces them. The defensive lesson is to treat AI platform content with the same scrutiny applied to any user-generated content: verify intent, monitor execution, and never assume platform hosting equals safety.