CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2threat

A malicious ChatGPT Custom GPT sends users to a Google Sites ClickFix page that installs a sideloaded, in-memory RAT

Huntress: a ChatGPT Custom GPT lure feeds a ClickFix chain that ends in a signed-host DLL sideload and a RAT

Analysis

Huntress reports a campaign from late September 2026 in which, in some incidents, victims who searched Google for "chatgpt" got a sponsored result that opened an attacker-built Custom GPT on the genuine chatgpt.com domain. It answers any input with a fake service-availability notice pointing to a "backup domain" on Google Sites, which shows a CAPTCHA and tells the user to paste a command into a terminal. The command fetches a layered, obfuscated script from a host written as a single decimal number, so "rules and URL filters that look for a dotted IP address never see one"; the script installs a hidden MSI with msiexec and deletes itself (Huntress, 2026-09-28).

The MSI presents itself as a printer-configuration reader, launches a legitimately signed Canon application, which loads a patched Canon logging DLL whose imports pull in unsigned DLLs; one XOR-decodes shellcode hidden in a file posing as audio. The shellcode bypasses AMSI, unhooks ntdll, runs anti-VM checks and hosts the .NET runtime, then opens a custom encrypted archive holding a persistence script and the remote access trojan. The script re-creates an HKCU Run value every 150 seconds and a scheduled task of the same name every 875 seconds if either is removed. The RAT offers remote desktop, camera, microphone and audio capture, file search and follow-on payload execution, and resolves its command server through DNS-over-HTTPS to public resolvers, "so they never appear in local DNS logs" (Huntress, 2026-09-28).

Huntress has responded to at least 40 incidents from the Google Sites domain and confirmed two through a Custom GPT. OpenAI took the first GPT down as of 2026-09-25; on 2026-09-27 Huntress found a replacement that swaps the signed host for a Stardock application, hides the loader in a Microsoft NuGet package, strips Mark-of-the-Web from the MSI and pulls a second script that is freshly obfuscated on every request, while the RAT is byte-identical (Huntress, 2026-09-28).

Exposure: any Windows endpoint whose user pastes the command; the chain uses no vulnerability, and staff who search for AI assistants are in scope.

Triage: the signed Canon and Stardock host binaries are legitimate (Huntress: do not block globally); the discriminator is the same binary launched by msiexec from a fake product folder under the user profile, beside a same-named Run value and scheduled task that return when deleted (Huntress, 2026-09-28).

Cited evidence

has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance

Most ClickFix chains we see are two or three hops: paste a command, download something, run it. This one has eight, and each hop exists to hide the next one.

rules and URL filters that look for a dotted IP address never see one

Detections tied to Canon or Stardock names will miss the next swap.

Kill the process first, then remove both.

Huntress 2026-09-28

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.