Cybersecurity researchers have uncovered a sophisticated social engineering campaign that leverages the official OpenAI domain to distribute a Remote Access Trojan (RAT). By creating malicious “Custom GPTs,” attackers are able to bypass traditional web filters and exploit the inherent trust users place in the ChatGPT ecosystem.
The campaign centers on a fraudulent bot named “Plus 5.6,” designed to impersonate an official OpenAI model upgrade. Because this bot is hosted directly on chatgpt.com, it presents a facade of legitimacy that standard security software often fails to flag. When a user interacts with the bot, it claims there is a server connectivity issue and directs the user to a “backup domain” hosted on Google Sites to continue the session.

The ‘ClickFix’ Social Engineering Trap
Once the user navigates to the external Google Sites page, they are met with a “ClickFix” attack. This technique uses a fake Cloudflare CAPTCHA or a simulated system error message to trick the victim into performing a manual software “fix.” In this instance, the site instructs the user to click a “Verify” button, which actually copies a malicious PowerShell command to the user’s clipboard.
The user is then prompted to open the Windows “Run” dialog (Win + R) and paste the command. This maneuver is highly effective because it moves the execution of the attack out of the browser environment—where many security controls live—and into the operating system’s native command line. According to research from Huntress, the PowerShell command uses decimal-formatted IP addresses to further evade automated URL filters that typically look for standard dotted-quad IP notation.
The campaign has shown significant persistence. OpenAI removed the original “Plus 5.6” GPT on September 25, 2026, following initial reports. However, researchers observed a replacement bot emerging just two days later, on September 27, 2026, indicating a dedicated effort by the threat actors to maintain their presence on the platform.
Advanced Obfuscation and DLL Sideloading
The attack chain is a multi-stage process designed to stay under the radar of antivirus programs. To deliver the final payload, the attackers utilize “DLL sideloading,” a method where a legitimate, digitally signed application is used to load a malicious file. In the early stages of the campaign, attackers used signed executables from Canon, such as COTFileReadApp.exe. Later iterations of the attack transitioned to using software signed by Stardock.
By using trusted, signed applications to initiate the malicious code, the attackers increase the likelihood that the activity will be ignored by endpoint detection systems. This chain eventually installs a Remote Access Trojan known as “@input.” This specific malware provides the attackers with comprehensive surveillance capabilities, including the ability to:
- Capture real-time screenshots of the victim’s desktop.
- Activate and record through the system’s webcam and microphone.
- Log keystrokes to steal credentials and financial data.
- Exfiltrate files from the infected machine.
Researchers at Huntress identified at least 40 distinct incidents stemming from the specific Google Sites domain used in this campaign. This suggests the attack is not a theoretical proof-of-concept but a live operation targeting ChatGPT users who may be seeking “Plus” features or advanced models through unofficial channels.
To avoid these traps, users should verify the creator of any Custom GPT. Official OpenAI tools will typically be labeled as such, and any prompt asking a user to run PowerShell commands or copy-paste text into the Windows Run box should be treated as a definitive indicator of a malware attempt.
















