PowerShell-triggered RAT payload on Windows
Malware Activity
Summary
Hide ▲
Show ▼
The PowerShell-triggered ClickFix chain deployed a remote access trojan (RAT) that gave operators remote desktop access, camera/audio capture, reconnaissance, and additional payload execution on Windows. The malware established persistence with a Run key and scheduled task named Canon Configuration Reader. Delivery used a malicious MSI and a modified DLL loaded through a legitimate signed application, helping the infection blend in. Later variants shifted from a Canon-signed host app to a Stardock-signed one while keeping the same payload.
Related Happenings
OpenAI custom GPT ClickFix RAT campaign
Campaign
H score33
First: 29.09.2026 23:59
Last: 29.09.2026 23:59
Sources 1
How related:
The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.
About this happening:
A malicious custom GPT campaign abused sponsored Google results and fake backup pages to push users into ClickFix execution chains that deployed RAT malware. The o...
OpenAI custom GPT ClickFix RAT campaign
CampaignHow related: The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.
About this happening: A malicious custom GPT campaign abused sponsored Google results and fake backup pages to push users into ClickFix execution chains that deployed RAT malware. The o...
Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Malware Activity
H score29
First: 26.09.2026 21:22
Last: 26.09.2026 21:22
Sources 1
About this happening:
Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...
Psychedelic Stealer / LunexStealer MaaS infostealer deployment
Malware ActivityAbout this happening: Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while kee...
ChainScript RAT delivered via ClickFix-like lures
Malware Activity
H score23
First: 21.09.2026 11:39
Last: 21.09.2026 11:39
Sources 1
About this happening:
The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
ChainScript RAT delivered via ClickFix-like lures
Malware ActivityAbout this happening: The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows system...
DeepLoad credential-stealing malware activity with WMI persistence
Malware Activity
H score30
First: 31.03.2026 00:25
Last: 31.03.2026 00:25
Sources 1
About this happening:
The DeepLoad malware strain is stealing credentials immediately after infection, exposing stored browser passwords, live keystrokes, and active accounts in enter...
DeepLoad credential-stealing malware activity with WMI persistence
Malware ActivityAbout this happening: The DeepLoad malware strain is stealing credentials immediately after infection, exposing stored browser passwords, live keystrokes, and active accounts in enter...
OAuth-phished ZIP/LNK/PowerShell malware delivery chain
Malware Activity
H score19
First: 03.03.2026 11:20
Last: 03.03.2026 11:20
Sources 1
About this happening:
ZIP-delivered malware now uses a PowerShell and DLL side-loading chain to infect Windows devices and reach an external C2 server, increasing the risk of follow-on...
OAuth-phished ZIP/LNK/PowerShell malware delivery chain
Malware ActivityAbout this happening: ZIP-delivered malware now uses a PowerShell and DLL side-loading chain to infect Windows devices and reach an external C2 server, increasing the risk of follow-on...
Timeline
-
29.09.2026 23:59 1 articles · 0h ago
OpenAI removes the Plus 5.6 custom GPT
Mitigation Patch UpdateOpenAI removed the custom GPT named Plus 5.6 after it was used to steer users from sponsored Google results to a Google Sites page that prompted a PowerShell command as part of the ClickFix infection chain.
Show sources
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59
-
29.09.2026 23:59 1 articles · 0h ago
Researchers find a second Plus 5.6 custom GPT still active
Campaign Scope UpdateResearchers later found a second custom GPT tied to the same campaign and still active, showing the operator kept a live lure after the first takedown.
Show sources
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59
-
29.09.2026 23:59 2 articles · 0h ago
Huntress identifies a custom GPT ClickFix campaign delivering RAT malware
Initial DisclosureHuntress identified the campaign as affecting dozens of users and tied at least 40 incidents to the Google Sites lure. The malicious path used a fake Cloudflare check, a PowerShell command, a malicious MSI, and a modified DLL to deploy a Windows RAT with remote desktop access, audio and camera capture, file searches, host reconnaissance, and additional payload execution, while persistence relied on a Run key and scheduled task named 'Canon Configuration Reader'.
Show sources
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware — www.bleepingcomputer.com — 29.09.2026 23:59