Malicious custom GPT 'Plus 5.6' funnels users into ClickFix RAT
Huntress found a weaponized ChatGPT Custom GPT that pushes victims through a Google Sites ClickFix page to a PowerShell-delivered RAT. At least 40 incidents investigated.
Attackers weaponized ChatGPT's Custom GPT feature to steer victims into a ClickFix attack ending in a full-featured remote access trojan, according to Huntress research published September 29. The MDR firm investigated at least 40 related incidents, including two confirmed infections driven by the malicious GPT.
The lure is the interesting part: a Custom GPT named "Plus 5.6", in some cases reached through a sponsored Google result for "chatgpt." Whatever the user typed, the GPT returned a fake "Service Availability Notice" pointing to a "backup domain" hosted on Google Sites.
How the chain works
The Google Sites page poses as a Cloudflare CAPTCHA and instructs the visitor to paste a command into their terminal — textbook ClickFix. Per Huntress, running the supplied PowerShell command installs a malicious MSI that launches a legitimate, signed application alongside a modified DLL that side-loads the malware.
The payload is a RAT with remote desktop access, audio and camera capture, file search, host reconnaissance, and the ability to run additional payloads. Later variants swapped in a Stardock-signed application to carry the DLL side-load.
What to hunt for
Huntress reports the malware establishes persistence via both a Registry Run key and a scheduled task, each named "Canon Configuration Reader." That naming is the highest-signal artifact to sweep for:
# Persistence names reported by Huntress, 2026-09-29
HKCU\...\Run\Canon Configuration Reader # Registry Run key
\Canon Configuration Reader # Scheduled task
These are the names Huntress observed; treat the Huntress writeup as the authoritative source for hashes and network indicators, and confirm against your own telemetry before blocking on the string alone.
Exploitation status
This is an active, in-the-wild campaign, not a proof-of-concept. BleepingComputer and Help Net Security corroborate the Huntress findings. OpenAI removed the first "Plus 5.6" GPT by September 25; researchers found a second active variant on September 27 — takedown-and-respawn, which is the norm for abuse of hosted platforms.
Action checklist
- Sweep for the persistence artifacts. Search endpoints for Registry Run keys and scheduled tasks named "Canon Configuration Reader," then pivot on any host that matches.
- Alert on
mshta/powershelllaunched from a browser or clipboard-paste context — the ClickFix pattern is a user pasting a command they were told to run. Block clipboard-to-terminal execution where you can. - Filter sponsored search abuse. The initial hook was a sponsored Google result impersonating ChatGPT. Warn users that "official" tools reached via ads are a common malware on-ramp.
- Don't trust "signed" as clean. The chain abuses legitimately signed binaries to side-load a malicious DLL — signature checks alone will not catch it. Look at what the signed process loads.
- Educate on ClickFix specifically. No legitimate CAPTCHA or "availability check" asks you to paste a command into PowerShell.
Context
ClickFix has become the default social-engineering primitive of 2026, and this is not the first time we've tracked it — see our earlier writeup on the Ghost CMS ClickFix campaign. What's new here is the delivery surface: a trusted AI platform's own Custom GPT feature used as the first stage. Expect more of it — hosted GPT/assistant marketplaces are a low-friction way to put attacker-controlled instructions in front of a user who already trusts the brand.