Skip to main content

Morning Overview

A fake Cloudflare check inside a sponsored ChatGPT link is installing a remote-access trojan

“Experiencing limited availability on the primary domain” is the message a malicious custom GPT called Plus 5.6 showed to people who reached it from a sponsored Google result for “ChatGPT.” The notice pointed them to a backup site on Google Sites, and the backup site put up a fake Cloudflare human check that told them to run a PowerShell command. That command started an eight-stage chain whose last link is a remote-access trojan.

Huntress, the managed security firm that documented the campaign, counted at least 40 incidents connecting to the Google Sites page.

The Plus 5.6 custom GPT and the sponsored Google result

The lure works because every hop looks legitimate. Huntress’s write-up says victims who searched Google for ChatGPT met paid ads leading to custom GPTs titled Plus 5.6, hosted on the genuine chatgpt.com domain, which borrowed the platform’s credibility. The interface imitated ordinary ChatGPT, then announced the availability problem, which Infosecurity Magazine describes as a fake “Service Availability Notice,” and steered the visitor toward the Google Sites mirror. Google Sites is Google’s own page-hosting service, so the second hop also sits on a well-known domain that few filters distrust. BleepingComputer’s account makes the same point: the real domain made compliance more likely.

The 40 figure needs care. Only two of those incidents were definitively tied to custom GPT variants, so the number measures traffic to the malicious page, not victims who arrived through ChatGPT.

OpenAI removed the first Plus 5.6 GPT by September 25, and Huntress found a second active variant on September 27, which Infosecurity Magazine reports it linked to the same operation as the first. SC Media reported that both had been taken down by Tuesday afternoon, September 29, after Huntress reported them to OpenAI. Sponsored placement is a separate lever: Google’s ads policy prohibits intentional distribution of malware in ads or on linked pages and treats violations as egregious, with immediate account suspension, yet the campaign was promoted in sponsored results anyway.

The ClickFix check and eight hops to a RAT

Timing shows how fast the operators adapted. Infosecurity Magazine dates the campaign to September, Help Net Security describes it as affecting dozens of users, and Huntress’s own security operations center responded to the 40-plus incidents tied to the Google Sites domain. With a replacement GPT live within two days of the first takedown, each removal cost the operators little.

ClickFix is the technique of persuading a visitor to execute the attack personally. Here the fake Cloudflare prompt instructs the visitor to paste a PowerShell command, and PowerShell downloads an obfuscated script. SC Media counts eight stages in the chain, with DLL sideloading, obfuscated scripts and encrypted payloads, and Huntress’s authors wrote that there were “eight, and each hop exists to hide the next one.”

Huntress’s analysis lists XOR encryption, stack-based string decoding and anti-virtual-machine checks among the obfuscation layers, which slows analysts and sandboxes alike. Along the way a loader hides inside WAV audio files, a malicious MSI package is installed, and legitimately signed Canon applications sideload an unsigned DLL. DLL sideloading abuses the trust placed in a signed program: the legitimate executable runs, loads the attacker’s library from the same folder, and security tools see a vendor-signed process doing the work. Later waves swapped Canon for Stardock-signed executables and added a custom encrypted file system with 1,128 entries to hold the persistence mechanism and the trojan itself.

Trojan capabilities and Huntress’s detection points

The payload provides remote desktop sessions, screen broadcasting, audio and video capture (SC Media counts support across 17 browsers), advanced file management, file search, file search, host reconnaissance and execution of further payloads in several formats. It persists through a Windows Registry Run key and a scheduled task, both named “Canon Configuration Reader,” a name that reads like routine printer software. Infosecurity Magazine adds that it can monitor systems and exfiltrate data, and SC Media’s summary says command-and-control traffic rides on DNS-over-HTTPS through Cloudflare, Google and Quad9 resolvers.

Huntress’s guidance for defenders is specific. PowerShell launching msiexec.exe to install MSI packages silently, signed applications starting from unusual %LOCALAPPDATA%\Programs\ locations, and Run values and scheduled tasks that survive deletion are the signals it recommends hunting for. Its researchers also state the rule that defeats the lure outright: no legitimate website, CAPTCHA or fix asks anyone to copy something into the Run dialog, Terminal, PowerShell or a command prompt, as Help Net Security quoted.

The gap between 40 and 2 is the unanswered part of the Huntress report: the firm has not said how many of the other victims reached the Google Sites page through a custom GPT and how many through other routes, so the share of infections that began inside a sponsored ChatGPT link is only known to be at least two.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview