Attackers are disguising malicious Custom GPTs as a new ChatGPT model, then steering victims to a fake “backup” site that delivers a remote access trojan.
Huntress researchers traced the campaign to at least 40 incidents, two of which they confirmed came through a Custom GPT.
Custom GPTs let users build tailored versions of ChatGPT with their own instructions, files, and tools. They live on the legitimate chatgpt.com domain. That is exactly why the attackers chose them.
Hackers Abuse ChatGPT Custom GPTs
Victims who searched Google for “chatgpt” saw a sponsored result. It led to a Custom GPT titled “Plus 5.6,” which is easy to mistake for a real model. The only hint is a small “community builder” label.
Any prompt triggers the same “Service Availability Notice.” It claims the primary domain is limited and tells users to upgrade or use a “backup domain.” That link points to a Google Sites page posing as a Cloudflare CAPTCHA check, which delivers the ClickFix lure.

The ClickFix step makes victims run a PowerShell command. It fetches a script from a host written as the decimal number 1614733393 instead of a dotted IP. Windows resolves it to 96.62.224[.]81, so filters looking for dotted IPs miss it.
The script is a single 27,581-character line, mostly an array of 3,036 negative integers. It decodes with a fixed key and runs in memory. A second layer hides every revealing string. The final script silently installs ISOSimple.msi and deletes itself.
The MSI poses as “Advanced Printer Configuration Reader” and hides itself from Programs and Features. It launches COTFileReadApp.exe, a genuine Canon-signed binary. A patched Canon logging library, ceiinfolog.dll, carries an extra import that pulls in the malicious rdCore.dll.
Persistence uses a Run key and a scheduled task, both named Canon Configuration Reader. Microsoft Defender quarantined the MSI in one case as Trojan:Script/Wacatac.H!ml. By then the installer had already run, and persistence kept the chain alive.
The rdCore.dll loader reads 341,395 bytes from a .wav file, starting at offset 0x24362. It decodes them with a rolling XOR and runs them as shellcode. The file has a valid WAV header, but the audio turns to ciphertext partway through. Huntress notes this is not true steganography.
The shellcode bypasses AMSI, unhooks ntdll, checks for virtual machines, and hosts the .NET runtime. It then unpacks monitor.raw, a custom encrypted archive with 315 folders and 806 files. Inside is a script that re-creates the Run key every 150 seconds and the scheduled task every 875 seconds.

The final payload is 1.58 MB of shellcode. It supports remote desktop, camera, microphone and system-audio capture. It also includes a file manager and supports 17 browsers. It can run follow-on EXE, DLL, MSI, PowerShell, VBScript, and other payloads.
It inventories antivirus, Defender status, domain details, and hardware. It finds its command server through DNS-over-HTTPS via Cloudflare, Google, and Quad9, so lookups skip local DNS logs. On most hosts, it then dropped the signed GOMCam2024.exe and launched Chrome with a throwaway profile.
Mitigation
OpenAI removed the first Custom GPT on September 25, but Huntress found a replacement on September 27. The second wave swaps in Stardock’s DeElevate64.exe, hides the loader in a Microsoft NuGet package (Build.dat), and strips Mark-of-the-Web before installing. The RAT itself is byte-for-byte identical.
Because names will keep changing, Huntress advises hunting for behaviors:
- PowerShell launching msiexec on a GUID-named MSI in %TEMP%.
- A signed app started by msiexec from a fake folder under %LOCALAPPDATA%\Programs.
- A Run value and scheduled task sharing one name that returns after deletion.
- Unsigned DLLs beside signed executables, such as ceiinfolog.dll, rdCore.dll, or DeElevator64.dll.
Responders should kill the process first, then remove both persistence entries. Huntress also found a third installer, UltraFreeISOCreateWizardSolution.msi, so more disguises are likely.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.