
If you searched for ChatGPT on Google recently and clicked the first result, there’s a chance you landed on a trap. Cybersecurity firm Huntress has reported an active campaign where criminals built custom ChatGPT models specifically designed to infect users with Remote Access Trojans, known as RATs. The attack is clever because it starts somewhere most people consider trustworthy: OpenAI’s own website.
Here’s how it works. A sponsored Google search ad for “chatgpt” directs users to a custom GPT called “Plus 5.6,” hosted on the official ChatGPT domain. Because the URL belongs to OpenAI, most people assume it’s legitimate. That assumption is exactly what the attackers are counting on. Once inside the chat, the bot displays a fake “Service Availability Notice” claiming servers are overloaded and nudges the user to visit a backup link on Google Sites instead.
That backup page is where things get ugly. It shows a fake Cloudflare verification check and uses a technique called ClickFix, a social engineering method that has been circulating in cybercriminal communities for the past couple of years. The page instructs the user to copy a line of code and paste it into a Windows PowerShell terminal. If they do, the command silently downloads an installer called ISOSimple.msi, which drops malware into a temporary folder and begins setting up the payload.
To slip past antivirus tools, the attackers used legitimate signed software to load their malicious code sideways. Early versions of the attack hid the payload inside what appeared to be a .WAV audio file and used a signed Canon application to run it. Later variants switched to a Stardock executable and concealed the code inside a Microsoft NuGet package. These are not amateur moves. Side-loading through trusted software is a well-documented evasion technique, and the fact that it’s being used here suggests some operational maturity behind this campaign.
Once fully installed, the RAT gives attackers remote desktop access, control over the victim’s files, and the ability to capture audio and video from the camera and microphone. The malware also writes a new Windows Registry key and creates a scheduled task named “Canon Configuration Reader” so it restarts automatically every time the system boots. Huntress tracked over 40 incidents connected to the Google Sites page alone, with at least two confirmed links back to custom GPTs.
OpenAI removed the original malicious model on September 25. Researchers found a second active variant just two days later. So the platform response, while real, is not keeping up. And there’s a deadline looming: OpenAI is scheduled to retire custom GPTs entirely on December 11. That suggests attackers are trying to extract as much damage as possible from the feature before it disappears.
The broader problem here is trust by association. Users see a link on OpenAI’s domain and reasonably conclude it’s safe. Google’s ad auction system, meanwhile, is still placing unverified sponsored results above organic search content, which means a malicious actor with a budget can buy their way to the top of results for high-value search terms. Neither platform is doing enough to verify what they’re promoting or hosting.
The ClickFix method is also worth paying attention to because it bypasses conventional network-level defenses entirely. There’s no malicious download to flag, no suspicious email attachment to block. The user runs the command themselves. That shifts the attack outside the reach of many standard security tools, and it works disturbingly well against people who aren’t already suspicious of CAPTCHA checks that ask you to open a terminal.
If you’re using Windows and you’ve searched for ChatGPT recently, it’s worth checking your scheduled tasks and registry for anything named after Canon software you don’t remember installing. And if any webpage ever asks you to open PowerShell and paste in a command, that’s not a CAPTCHA. Close the tab.