Plus 5.6 on chatgpt.com: A Fake Custom GPT and Its Eight-Stage Run to a Full RAT
Attackers built a fake ChatGPT model called "Plus 5.6", promoted it through sponsored Google results, and used it to funnel victims into a ClickFix trap that ends — eight stages later — in a full-featured remote access trojan with camera, microphone, and file-manager capabilities. Huntress published the teardown on 28 September 2026 after its SOC responded to at least 40 incidents tied to the campaign's Google Sites domain, two of them confirmed to have entered through the Custom GPT. OpenAI removed the first GPT on 25 September; researchers found a replacement on 27 September, still active at publication, running the same kit in a new costume. The campaign has since drawn wider press coverage — but the Huntress original remains the authoritative technical record, and its details deserve a careful briefing: this is AI-platform abuse maturing from link-sharing tricks into maintained delivery infrastructure.
The pattern is an escalation of things this site has tracked all year: SEO-poisoned ChatGPT share links used as malvertising and ClickFix lures hiding in agent-skill documentation. Huntress notes the same actors' season explicitly — Claude Artifacts abused as fake download pages, shared ChatGPT conversations pushing Terminal commands, a sponsored result pointing Mac users at a shared Claude conversation that dropped the MacSync stealer. The Custom GPT is the newest trusted surface to be weaponized, and the most potent: it lives on the legitimate chatgpt.com domain, carries the platform's own chrome, and answers the victim interactively.
The lure: a model that doesn't exist
In several incidents the attack started with a Google search for "chatgpt". A sponsored result — carrying Google Ads click-tracking parameters — placed the attacker's Custom GPT page above organic results, on the genuine ChatGPT domain. The GPT was titled "Plus 5.6" so visitors would mistake it for a new model; the "community builder" byline underneath is the only visible tell. Every interaction returned the same programmed message: a "Service Availability Notice" claiming limited availability on the primary domain, offering a subscription upgrade or continued service through a "backup domain" — a Google Sites page posing as a Cloudflare CAPTCHA check. That page is the ClickFix lure: instructions to paste a command into a terminal, which launches PowerShell with execution policy bypassed. Huntress's small, telling detail: the command's server is written as a decimal integer (1614733393) rather than a dotted IP (96.62.224.81) — Windows resolves it fine, while rules and URL filters looking for dotted quads never see it.
Eight stages, each hiding the next
Most ClickFix chains Huntress sees run two or three hops. This one runs eight. The pasted command downloads a single-line, ~27,000-character PowerShell stager — nearly all of it one array of 3,036 negative integers, each shifted by a fixed key and rebuilt in memory via scriptblock so the decoded version never touches disk — which silently installs an MSI calling itself "Advanced Printer Configuration Reader" from a publisher named "Softplicity". The installer hides from Programs and Features, launches its payload immediately, and deletes the stager. In at least one incident Microsoft Defender quarantined the MSI as Trojan:Script/Wacatac.H!ml — after it had already run, with the Run key and scheduled task carrying the chain forward anyway.
The MSI's trick is DLL sideloading through a genuinely Canon-signed binary. COTFileReadApp.exe from Canon CaptureOnTouch is legitimate and its signature verifies; its companion Canon logging library, ceiinfolog.dll, is mostly the real 2015 Canon code — but its signature is stripped, its header checksum no longer matches, and its import table carries one entry no logging library needs: the malicious rdCore.dll, dressed in version info claiming to be the Polly .NET resilience library. Windows loads the whole import table before the library's own code runs, so the Canon app launches the malware without a byte of Canon code changing. rdCore then reads 341,395 bytes of ciphertext stashed past offset 0x24362 inside a valid .wav file — real audio up front, encrypted loader after — and executes the decoded x64 shellcode, which blinds AMSI, hosts the .NET runtime from memory, unhooks ntdll, and checks for six hypervisor families before showing the victim a fake "LOADING..." window.
The shellcode's target is monitor.raw: not a blob but a homemade encrypted filesystem — header, 1,128-entry scrambled index, 315 folders and 806 files — holding a persistence script in the malware's own scripting language and the final 1.58 MB RAT payload. The script re-creates an HKCU Run value every 150 seconds and a scheduled task every 875 seconds, both named "Canon Configuration Reader", both launching the Canon binary — so the order of cleanup matters: kill the process first, then remove both, or the implant restores itself within minutes. The RAT itself runs remote desktop sessions and screen broadcasts, captures camera, microphone, and system audio, profiles 17 browsers, searches file contents host-wide, and resolves its "Gate" C2 over DNS-over-HTTPS through Cloudflare, Google, and Quad9 — inside ordinary HTTPS to well-known resolvers, invisible to local DNS logs. The C2 address itself was never recovered from any sample. On investigated hosts the RAT's first move was usually dropping a signed GOMCam binary to launch Chrome under a throwaway profile.
Version two: same engine, new paint
The replacement GPT found on 27 September served the identical kit with swapped wrapping: the signed host became Stardock's DeElevate64.exe, the patched DLL its DeElevator64.dll, and the WAV carrier a genuine Microsoft NuGet package (Build.dat) with the loader stitched into compressed DLL data — no audio-to-noise seam to catch. Delivery hardened too: a two-stage script with per-request obfuscation (every fetch a fresh hash), a spoofed Chrome user agent, three download retries, Mark-of-the-Web stripping so the MSI runs as if never downloaded, and a sandbox check that opens a harmless window instead of the payload when something looks off. The RAT binary is byte-identical across versions. Huntress also found a third installer on the same server, UltraFreeISOCreateWizardSolution.msi, never obtained — a strong hint more signed hosts are queued. Detections keyed to Canon or Stardock names will miss the next swap; the behaviors carry over: PowerShell launching msiexec on a GUID-named MSI in %TEMP%, a signed app started by msiexec from a bogus product folder, and a Run value plus scheduled task sharing one self-healing name.
What to do
- Detect the behaviors, not the brand names. powershell.exe → msiexec on a GUID-named MSI in %TEMP%; a signed app running from %LOCALAPPDATA%\Programs\ instead of a real vendor install path, especially when msiexec started it; a Run value and scheduled task sharing one name that returns after deletion. Huntress's detection list transfers directly into EDR rules.
- Flag decimal- and hex-encoded IPs in command lines. The 1614733393 trick is old but still defeats naive URL and IP matching. Normalize command-line network indicators before matching — PowerShell with irm against a bare integer host is worth an alert on its own.
- Treat "community builder" AI content as untrusted user input. Custom GPTs, shared conversations, Artifacts, and skills inherit the platform's domain reputation while executing stranger-written instructions. Train users that chatgpt.com in the address bar authenticates the platform, not the content — and that no legitimate CAPTCHA ever asks you to paste commands into a terminal.
- Watch sponsored results as an attack surface. Paid placement above organic results was the campaign's top-of-funnel. Brand-monitoring that covers ad inventory, not just domains and social accounts, catches the lure before the click.
- Verify DLL integrity beside signed hosts, not just the signature. An unsigned or checksum-mismatched ceiinfolog.dll next to a valid Canon binary was the whole attack. Allow-listing by signer without directory-hygiene checks blesses exactly this sideloading shape.
Our write-up is analysis of Huntress's published findings; we did not handle the samples. Chain details, hashes, dates, and incident counts are as Huntress reported on 28 September 2026.
Sources: