Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-01 · updated: 2026-10-01 · tags: [incident, global] · confidence: medium · severity: medium · affected_sectors: [global] · au_impact: true

Huntress observed a campaign in late September in which attackers stand up Custom GPTs — personalised ChatGPT variants hosted on the legitimate ChatGPT site — named to look like product offerings, including one called "Plus 5.6", and reach victims through sponsored Google search results for terms such as "chatgpt". The Custom GPT answers prompts with a Google Sites link framed as a backup domain for "limited availability"; the linked page presents a fake Cloudflare CAPTCHA, which is the ClickFix step that talks the victim into copying and running a PowerShell command. That command deploys an MSI installer, ISOSimple.msi, which runs a DLL sideloading chain abusing a legitimate Canon-signed binary to load shellcode, install a persistence script and launch a RAT. Huntress says at least 40 users were infected. It is the latest instance of attackers borrowing a trusted AI platform's surface — earlier campaigns used shared chatbot conversations and malicious Claude artifacts — and it needs no vulnerability in the platform itself.

Attribute Detail
Sector Global (Macro)
Date 2026-10-01
Source The Hacker News
Reliability Tier 2