chiprook
← Security
SecuritySeptember 29, 2026, 18:55

Malicious Custom GPT on chatgpt.com pushed users to install RAT

Attackers used sponsored Google results to promote a malicious Custom GPT called "Plus 5.6" on chatgpt.com, which led users to a fake Cloudflare CAPTCHA and a ClickFix attack that had them paste a command into Terminal. Huntress reported at least 40 incidents, with a RAT sideloaded via signed Canon and Stardock executables. OpenAI removed the first GPT, but the campaign returned.

Malicious Custom GPT on chatgpt.com pushed users to install RAT
#OpenAI#ChatGPT#Google
Read next
Security

Malicious npm packages evade install-script defenses at runtime

Security

Fake LastPass Installers Pushed Kernel Driver That Killed 145 Security Tools

Security

Fake "locked computer" alerts in Google Ads push users to call tech-support scammers

Business

Tailscale hits 40,000 business customers and 2.5M monthly users