Huntress researchers identified the campaign after investigating at least 40 incidents linked to a Google Sites page used in the attack. The threat actor created a custom GPT named 'Plus 5.6' that directed users to an alleged backup site hosted on Google Sites. The site displayed a fake Cloudflare check and instructed visitors to run a PowerShell command, which deployed a multi-stage infection chain.
The PowerShell command installs a malicious MSI that launches a legitimate, signed application and a modified DLL that loads the remote access trojan. The RAT provides capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads. For persistence, the malware creates a Run key and a scheduled task, both named 'Canon Configuration Reader', though more recent attacks switched to a Stardock-signed application.
OpenAI removed the first malicious GPT by September 25, but a second variant was found active on September 27. The company plans to retire the custom GPTs feature entirely on December 11, which may limit future abuse.
Huntress noted the attackers built a custom encrypted file system to conceal the persistence script and RAT. "Instead of one encrypted blob, it's a custom archive with its own folder tree, basically a homemade, encrypted zip file," the researchers said.
The attack chain is similar to past ClickFix campaigns that used deceptive ChatGPT conversations, but this is the first known abuse of the custom GPT feature.