New A malicious Custom GPT hosted on chatgpt.com walked users into installing a remote access trojan
Huntress researchers Mark O'Halloran and Jonathan Semon describe a Custom GPT named “Plus 5.6,” hosted on chatgpt.com, that sent users to a page on Google Sites presenting as a Cloudflare CAPTCHA check and running a ClickFix lure telling them to paste a command into their terminal, starting an eight-stage chain that sideloaded a remote access trojan through the legitimately signed Canon binary COTFileReadApp.exe and Stardock's DeElevate64.exe. They write that “the Huntress SOC has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came through a Custom GPT instance.” Huntress says it “reached out to OpenAI regarding this specific Custom GPT, and it was taken down as of September 25; however, on September 27 Huntress researchers discovered a new Custom GPT linked to the same campaign.” The post assigns no CVE.