Find notable cyber news and cases, enriched with sources, timelines, and signals.

PowerShell-triggered RAT payload on Windows

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The PowerShell-triggered ClickFix chain deployed a remote access trojan (RAT) that gave operators remote desktop access, camera/audio capture, reconnaissance, and additional payload execution on Windows. The malware established persistence with a Run key and scheduled task named Canon Configuration Reader. Delivery used a malicious MSI and a modified DLL loaded through a legitimate signed application, helping the infection blend in. Later variants shifted from a Canon-signed host app to a Stardock-signed one while keeping the same payload.

Related Happenings

OpenAI custom GPT ClickFix RAT campaign

Campaign
H score33 First: 29.09.2026 23:59 Last: 29.09.2026 23:59 Sources 1

How related: The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.

About this happening: A malicious custom GPT campaign abused sponsored Google results and fake backup pages to push users into ClickFix execution chains that deployed RAT malware. The o...

Psychedelic Stealer / LunexStealer MaaS infostealer deployment

Malware Activity
H score29 First: 26.09.2026 21:22 Last: 26.09.2026 21:22 Sources 1

About this happening: Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...

ChainScript RAT delivered via ClickFix-like lures

Malware Activity
H score23 First: 21.09.2026 11:39 Last: 21.09.2026 11:39 Sources 1

About this happening: The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...

DeepLoad credential-stealing malware activity with WMI persistence

Malware Activity
H score30 First: 31.03.2026 00:25 Last: 31.03.2026 00:25 Sources 1

About this happening: The DeepLoad malware strain is stealing credentials immediately after infection, exposing stored browser passwords, live keystrokes, and active accounts in enter...

OAuth-phished ZIP/LNK/PowerShell malware delivery chain

Malware Activity
H score19 First: 03.03.2026 11:20 Last: 03.03.2026 11:20 Sources 1

About this happening: ZIP-delivered malware now uses a PowerShell and DLL side-loading chain to infect Windows devices and reach an external C2 server, increasing the risk of follow-on...

Timeline

  1. 29.09.2026 23:59 1 articles · 0h ago

    OpenAI removes the Plus 5.6 custom GPT

    Mitigation Patch Update

    OpenAI removed the custom GPT named Plus 5.6 after it was used to steer users from sponsored Google results to a Google Sites page that prompted a PowerShell command as part of the ClickFix infection chain.

    Show sources
  2. 29.09.2026 23:59 1 articles · 0h ago

    Researchers find a second Plus 5.6 custom GPT still active

    Campaign Scope Update

    Researchers later found a second custom GPT tied to the same campaign and still active, showing the operator kept a live lure after the first takedown.

    Show sources
  3. 29.09.2026 23:59 2 articles · 0h ago

    Huntress identifies a custom GPT ClickFix campaign delivering RAT malware

    Initial Disclosure

    Huntress identified the campaign as affecting dozens of users and tied at least 40 incidents to the Google Sites lure. The malicious path used a fake Cloudflare check, a PowerShell command, a malicious MSI, and a modified DLL to deploy a Windows RAT with remote desktop access, audio and camera capture, file searches, host reconnaissance, and additional payload execution, while persistence relied on a Run key and scheduled task named 'Canon Configuration Reader'.

    Show sources