Skip to content

Executive Summary

A Custom GPT feature is being utilized as a delivery mechanism for malicious software, as observed in at least 40 incidents by Huntress researchers. The method involves leading victims to a seemingly legitimate Custom GPT page that redirects them to a backup domain hosting a fake Cloudflare CAPTCHA. This leads the victim to execute a PowerShell command via a ClickFix attack, which downloads and installs a malicious MSI file.
The malware infection chain involves several sophisticated steps. It uses DLL sideloading by modifying a legitimately signed Canon application to load malicious code from an injected library. This payload then extracts data from an encrypted WAV file using XOR cipher and unpacks a custom, heavily encrypted archive containing persistence scripts and a Remote Access Trojan (RAT). The RAT establishes command and control via DNS-over-HTTPS traffic and accesses system resources.
The attackers also employed different delivery methods, including variants signed by Stardock or hiding the payload within legitimate NuGet packages, demonstrating an evolving adaptation of the attack framework. The consistent technical sequence involves using PowerShell to install an MSI, sideloading from signed binaries, establishing persistence, and deploying a RAT.

Facts Only

* A Custom GPT feature is used as a delivery mechanism for malicious software in at least 40 incidents.
* Victims are directed to a Custom GPT page linked from a Google search result to initiate the attack.
* The victim is redirected to a backup domain hosting a fake Cloudflare CAPTCHA.
* This leads to executing a PowerShell command via a ClickFix attack.
* The PowerShell command downloads and installs a malicious MSI.
* The malware uses DLL sideloading through a legitimately signed Canon application (COTFileReadApp.exe) to inject code from a modified logging library.
* An encrypted loader is extracted from a WAV file, which decodes into a payload archive containing persistence scripts and a RAT.
* The RAT establishes command and control using DNS-over-HTTPS traffic.
* Subsequent versions used Stardock-signed binaries or embedded the loader in NuGet packages instead of WAV files.
* Detection advice includes monitoring PowerShell launching msiexec on GUID-named MSIs in the temp folder, specific file names under AppData, and persistence mechanisms like Run keys or scheduled tasks.

Full Take

The operational pattern reveals a systemic exploitation of platform trust, leveraging emerging features like Custom GPTs to bypass traditional security measures. The attack is not reliant on any single exploit but follows a consistent multi-stage framework: social engineering entry point $\rightarrow$ initial execution via ClickFix $\rightarrow$ privilege escalation/persistence via signed binary manipulation (DLL sideloading) $\rightarrow$ final objective deployment (RAT). This structure demonstrates that the effectiveness of the threat lies less in the specific malware variant and more in the predictable chain of trust exploitation.
The evolution seen across different variants—changing signatures, file names, and embedding locations (WAV vs. NuGet)—indicates a deliberate effort to evade signature-based detection systems while preserving the core operational logic. This forces security defenses to move away from static artifact monitoring toward behavioral analysis focusing on the invariant sequence of actions: PowerShell execution leading to legitimate application sideloading followed by covert persistence establishment.
The implications suggest that trust in platform features, even those marketed as user-friendly assistants, becomes a critical vulnerability. When platforms become entry points for social engineering vectors, defenses must account for the *behavior* that follows interaction rather than just monitoring the initial interaction itself. The evasion techniques, such as building custom encrypted archives and using legitimate binaries for deception, highlight the persistence of low-level system exploitation principles masked by high-level platform abuse.
Bridge Questions: If trust in platform features is the vulnerability, what systems or cultural shifts are necessary to re-establish fundamental security boundaries around these interaction points? How can defense models shift from identifying known malicious artifacts to recognizing and disrupting the consistent behavioral chain across seemingly legitimate applications? What responsibility exists for developing controls that protect user agency when the attack vector originates from widely trusted, evolving AI interfaces?

From the original · Security Affairs (Pierluigi Paganini)

ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a GPT) is essentially a version of ChatGPT that you configure for one specific job.
Read the full story at securityaffairs.com

Sentinel — Human

Confidence

The text reads like a detailed, human-authored summary of high-level threat research, skillfully weaving together technical findings with contextual implications.

Signals Detected
low severity: Sentence length variance and complex technical explanation structure suggest human editorial pacing.
low severity: Deep, specific immersion in a highly technical chain of events with nuanced interpretation points toward expert authorship.
medium severity: Consistent articulation of complex, multi-stage attack methodologies (DLL sideloading, custom encryption) suggests specialized source material integration rather than generic pattern matching.
low severity: The presence of highly specific, verifiable technical details and citations (e.g., names like Canon, Stardock, specific file structure descriptions) anchors the text in observable reality.
Human Indicators
Use of subjective framing ('worth pausing on,' 'considerably less convenient') balances objective reporting with analytical commentary.
The transition between narrative storytelling (the attack steps) and forensic analysis (DLL sideloading mechanisms) shows a human structuring of complex information for readability.
Attackers Abuse ChatGPT Custom GPTs to Deploy a Full | Huntaegis