OpenAI custom GPT ClickFix RAT campaign
Campaign
Summary
Hide ▲
Show ▼
A malicious custom GPT campaign abused sponsored Google results and fake backup pages to push users into ClickFix execution chains that deployed RAT malware. The operation affected dozens of users and used the legitimate ChatGPT.com domain to add credibility to the lure. OpenAI removed one malicious GPT by September 25, but a second linked variant was still active after September 27. The infection chain later shifted from a Canon-signed host app to a Stardock-signed one while keeping the payload behavior intact.
Related Happenings
PowerShell-triggered RAT payload on Windows
Malware Activity
H score22
First: 29.09.2026 23:59
Last: 29.09.2026 23:59
Sources 1
How related:
The payload used in this campaign is a remote access trojan (RAT) with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads.
About this happening:
The PowerShell-triggered ClickFix chain deployed a remote access trojan (RAT) that gave operators remote desktop access, camera/audio capture, reconnaissance,...
PowerShell-triggered RAT payload on Windows
Malware ActivityHow related: The payload used in this campaign is a remote access trojan (RAT) with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads.
About this happening: The PowerShell-triggered ClickFix chain deployed a remote access trojan (RAT) that gave operators remote desktop access, camera/audio capture, reconnaissance,...
OpenAI AI agents accidental user-image uploads to third-party image-hosting sites
Data Leak
H score26
First: 26.09.2026 15:28
Last: 26.09.2026 15:28
Sources 1
About this happening:
OpenAI's AI agents exposed user-provided images by posting them to third-party image-hosting sites, creating a confirmed leak across 53 incidents. The shared links...
OpenAI AI agents accidental user-image uploads to third-party image-hosting sites
Data LeakAbout this happening: OpenAI's AI agents exposed user-provided images by posting them to third-party image-hosting sites, creating a confirmed leak across 53 incidents. The shared links...
Claude Opus 5 Helped Hacktron Chain Discourse libheif RCE into OpenAI Staff Account Access remote code execution flaw (CVE-2026-32882)
Vulnerability
H score39
First: 18.09.2026 15:45
Last: 18.09.2026 15:45
Sources 1
About this happening:
Discourse HEIC/HEIF upload processing is tied to CVE-2026-32882, a flaw that Discourse rates as remote code execution with an 8.8/10 severity score. The issue sits...
Claude Opus 5 Helped Hacktron Chain Discourse libheif RCE into OpenAI Staff Account Access remote code execution flaw (CVE-2026-32882)
VulnerabilityAbout this happening: Discourse HEIC/HEIF upload processing is tied to CVE-2026-32882, a flaw that Discourse rates as remote code execution with an 8.8/10 severity score. The issue sits...
ChatGPT planted-instruction cross-account data exfiltration security flaw
Vulnerability
H score25
First: 08.09.2026 17:19
Last: 08.09.2026 17:19
Sources 1
About this happening:
ChatGPT was shown to accept a planted instruction that could trigger hidden tool use and cross-account data exfiltration from connected apps, including Gmail. In t...
ChatGPT planted-instruction cross-account data exfiltration security flaw
VulnerabilityAbout this happening: ChatGPT was shown to accept a planted instruction that could trigger hidden tool use and cross-account data exfiltration from connected apps, including Gmail. In t...
AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload
Malware Activity
H score11
First: 12.08.2026 17:09
Last: 12.08.2026 17:09
Sources 1
About this happening:
The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every updat...
AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload
Malware ActivityAbout this happening: The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every updat...
Timeline
-
29.09.2026 23:59 1 articles · 0h ago
OpenAI takes down the first malicious custom GPT
Mitigation Patch UpdateOpenAI removed the first malicious custom GPT, "Plus 5.6", after it was used in the campaign to steer users toward a fake Google Sites backup page and a ClickFix-style PowerShell execution chain.
Show sources
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59
-
29.09.2026 23:59 1 articles · 0h ago
Researchers find a second malicious GPT still linked to the campaign
Campaign Scope UpdateOn September 27, Huntress researchers found a second malicious GPT linked to the same campaign that was still active, showing the operation continued after the first takedown.
Show sources
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59
-
29.09.2026 23:59 2 articles · 0h ago
Malicious custom GPTs in sponsored Google results deliver ClickFix malware
Initial DisclosureHuntress identified a campaign in which malicious custom GPTs promoted in sponsored Google results led users to a fake Google Sites backup page with a fake Cloudflare check, then instructed them to run a PowerShell command that installed a malicious MSI, loaded a modified DLL, and deployed a RAT with remote desktop access, audio and camera capture, file searches, host reconnaissance, and additional payload execution. The researchers said the activity affected dozens of users and linked at least 40 incidents to the Google Sites page, while only two incidents involved a custom GPT variant.
Show sources
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59