Investigators reported finding another campaign-linked Custom GPT on September 27, two days after the first identified lure, “Plus 5.6,” was taken down. The reported route began with a sponsored Google result and ended in a remote-access trojan infection—but only after a person followed the page’s instructions and ran a command.
Another campaign-linked GPT was reported on September 27
The first identified Custom GPT, called “Plus 5.6,” was taken down on September 25 after investigators notified OpenAI. Investigators reported finding another GPT linked to the campaign on September 27.
How the reported route moved from an ad to malware
In some investigated incidents, a sponsored Google result led to an attacker-created Custom GPT hosted on the legitimate ChatGPT domain. The GPT directed users to a separate Google Sites page that imitated a Cloudflare CAPTCHA and presented ClickFix instructions. The familiar ChatGPT domain did not make the external destination safe.
Following those instructions and running a command started the documented infection chain. PowerShell fetched scripts and a malicious MSI, which installed silently; the chain ended with a remote-access trojan, or RAT. A RAT can give an attacker remote access to an infected computer.
What the incident count measures
Investigators associated at least 40 incidents with the specific Google Sites page and confirmed that two began through a Custom GPT. The two confirmed cases were included in the broader incident count.
Capabilities found in analyzed RAT samples
Analyzed samples had capabilities for remote desktop sessions and screen broadcasts, camera and microphone capture, host reconnaissance, file searches, persistence and running additional payloads. These are capabilities found in the samples, not a record of what was used against each person. The analyzed delivery variants also used legitimate Canon- and Stardock-signed applications as hosts.