A custom GPT titled Plus 5.6 has been sending people who search for ChatGPT to a counterfeit Cloudflare verification page, where a pasted PowerShell command installs a remote access trojan. The security firm Huntress documented the campaign, and OpenAI removed the first version of the GPT on September 25. A replacement was already live two days later.
The trick depends on where the instructions sit. Everything the victim reads before the fake check appears on chatgpt.com, a domain that browsers, email filters and wary users all treat as trustworthy, and that trust is the asset the attackers are borrowing.
A GPT that announces an outage and offers a backup site
According to Huntress’s technical analysis, victims reached the malicious Custom GPT through sponsored search results for the term “chatgpt.” The GPT, named Plus 5.6, displayed a fabricated service-availability notice and pointed visitors to a “backup domain.” SecurityWeek’s summary adds that the GPT was falsely attributed to a “community builder,” a label that makes it look like a hobbyist contribution rather than an attack.
The backup domain turned out to be a page on Google Sites, another legitimate hosting service that gives the lure a second layer of borrowed reputation, so neither hop in the chain looks like an obviously hostile address. A person who checks the browser bar sees two household names in a row and has little reason to stop. BleepingComputer, reporting the Huntress findings, noted that in both attacks the malicious instructions were hosted on the legitimate ChatGPT.com domain, “lending legitimacy to the operation and increasing the chances the victim will follow the instructions.”
The fake Cloudflare check and the PowerShell paste
The Google Sites page imitated a Cloudflare challenge. Real Cloudflare checks, such as the ones built on Turnstile, are designed to run without asking visitors to do anything beyond a click, which is why a check that wants commands typed into the operating system should stand out. The fake page told visitors to run a PowerShell command to prove they were human.
Security teams label the pattern ClickFix, and it has become one of the most common ways to get malware onto a machine without exploiting any flaw at all. Microsoft’s threat intelligence team has written that because the technique relies on human intervention to launch the commands, a campaign using it “could get past conventional and automated security solutions.” Nothing is exploited in the browser. The victim opens a Run dialog or terminal, pastes, and presses Enter, and the endpoint tooling sees a user doing something on purpose, with the user’s own permissions and the user’s own clipboard content.
Huntress found the command was obfuscated. It wrote the download address as a single decimal number, 1614733393, which resolves to an ordinary IPv4 address, and it layered two rounds of XOR encoding with fixed keys. Both tricks aim at string-matching filters rather than at a person reading the paste.
Signed Canon and Stardock files carrying the trojan
The PowerShell code fetched an MSI installer called ISOSimple.msi, registered under the product name “Advanced Printer Configuration Reader.” In the first variant the installer dropped a genuine, signed Canon executable, COTFileReadApp.exe, beside a patched, unsigned library named ceiinfolog.dll. When the signed program started, it loaded the altered library, which in turn pulled in the malicious rdCore.dll. This is DLL sideloading, and it lets the malicious code run inside a process that security products have reason to trust.
The second variant, which appeared after the first takedown, swapped in Stardock’s DeElevate64.exe with a matching DeElevator64.dll and hid its loader in a NuGet package instead of an audio file. Huntress reported that the loader was decrypted through an eight-stage chain that ended in a full-featured trojan. BleepingComputer’s account lists remote desktop access, audio and camera capture, file searches, host reconnaissance and the ability to run further payloads.
Persistence follows the same disguise. The malware writes a Run key in the registry and a scheduled task, both named “Canon Configuration Reader” in the first version and “Stardock DeElevation Tool” in the second, so that the signed host program relaunches after every restart. A name like that is unlikely to draw attention in a list of scheduled tasks on a home or office PC, and the registry entry sits under the current user’s hive, which needs no administrator rights to write. Huntress also described the trojan as able to manipulate 17 browsers, giving the operators a route into whatever accounts the victim has signed in to.
Scale, takedowns and a December cutoff
Huntress said it investigated at least 40 related incidents and traced two infections directly to interactions with a Custom GPT. OpenAI removed the first GPT on September 25, Huntress found a second active one on September 27, and the firm warned that the operators “are continuing to rely on this technique.”
BleepingComputer also reported that OpenAI plans to retire custom GPTs on December 11, a date that would end this particular delivery route but not the ClickFix method itself. Huntress has published the file names, registry entries and task names above so defenders can search for them directly, which is the most practical check for an administrator who suspects an affected machine: look for the Canon or Stardock task names, the unsigned library next to a signed executable, and the ISOSimple installer.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Four U.S. startups fired up their first small nuclear reactors, aiming to power AI data centers on-site
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- Doctors warn a silent liver disease now affects one in three American adults
- Hackers are hijacking outdated home routers, and the FBI named the models to check