<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs" -->

---
title: Attackers turned ChatGPT&#x27;s own domain into a ClickFix lure
description: A remote access trojan campaign is abusing malicious Custom GPTs hosted directly on chatgpt.com, including one named &#x27;Plus 5.6,&#x27; to lure victims through Google...
canonical: https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Attackers turned ChatGPT&#x27;s own domain into a ClickFix lure | daily.dev
og:description: A remote access trojan campaign is abusing malicious Custom GPTs hosted directly on chatgpt.com, including one named &#x27;Plus 5.6,&#x27; to lure victims through Google...
og:url: https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs
og:image: https://api.daily.dev/og/posts/pTODxRoFs.png
og:image:alt: Attackers turned ChatGPT&#x27;s own domain into a ClickFix lure
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Attackers turned ChatGPT's own domain into a ClickFix lure

**[Trends](https://daily.dev/sources/trends)** · 2 min read · 0 upvotes · 1 comments

## Summary

A remote access trojan campaign is abusing malicious Custom GPTs hosted directly on chatgpt.com, including one named 'Plus 5.6,' to lure victims through Google Ads into a ClickFix attack. Victims land on a Google Sites page styled as a Cloudflare CAPTCHA that tricks them into pasting and running a PowerShell command. The resulting infection chain is elaborate: an MSI abuses a signed Canon binary to sideload a patched DLL, hides a loader in a .wav file, and unpacks a RAT from an encrypted archive, which then offers remote desktop access, webcam/mic capture, browser credential theft, and file search, communicating over DNS-over-HTTPS and persisting via a Run key and scheduled task both named 'Canon Configuration Reader.' OpenAI removed one malicious GPT by September 25, but a second variant using a Stardock-signed binary and a NuGet-hidden loader was still live two days later. Huntress reports responding to over 40 related incidents. The researchers argue that domain-trust heuristics are obsolete when both OpenAI's and Google's legitimate domains are used as the lure, and security training needs to shift toward scrutinizing what a page asks a user to do. Separately, OpenAI plans to retire Custom GPTs entirely on December 11.

## Content

The scariest part of this RAT campaign isn't the malware. It's that the bait lives on chatgpt.com, so the usual advice (check the domain, look for the padlock) does nothing.

Huntress found malicious Custom GPTs, including one called "Plus 5.6", that show a fake "service unavailable" message. Per one writeup, it was promoted through Google Ads. Victims get bounced to a Google Sites page dressed up as a Cloudflare CAPTCHA, which asks them to paste a PowerShell command to "verify" themselves. That's the whole ClickFix trick: the victim runs the payload themselves.

From there it gets elaborate. One analysis counts an eight-stage chain. An MSI abuses a legitimately signed Canon binary (COTFileReadApp.exe) to sideload a patched DLL. The loader hides inside a .wav file, and the RAT unpacks from an encrypted archive called monitor.raw. The finished trojan offers remote desktop, webcam and mic capture, browser theft, file search, and follow-on payloads. It talks to its C2 over DNS-over-HTTPS, and persists through a Run key and a scheduled task both named "Canon Configuration Reader."

The cleanup story is the unflattering part. OpenAI pulled the first GPT by September 25, but a second one from the same campaign was still live on September 27. A second variant swaps the Canon app for a Stardock-signed binary and hides the loader in a NuGet package, while reusing the same RAT. Huntress says it has responded to at least 40 related incidents.

The researchers' takeaway is the useful one. Training has to move away from "is this domain trustworthy" toward "what is this page asking me to do." No legitimate service needs you to paste PowerShell to prove you're human. When both OpenAI's and Google's domains are doing the luring, that's the only check left.

One dry footnote: OpenAI plans to retire custom GPTs entirely on December 11. Good timing, if you squint.

## Questions this post answers

### What is the ClickFix attack technique and how does it trick users into running malware?

ClickFix is a social engineering technique where victims are shown a fake verification page, such as a spoofed Cloudflare CAPTCHA, that instructs them to paste and run a PowerShell command themselves to 'prove they are human.' In one campaign, victims reached this lure via malicious Custom GPTs hosted on chatgpt.com and promoted through Google Ads, meaning the malicious payload is self-executed by the victim rather than delivered directly.

_Security teams tracking emerging social-engineering tactics like this can follow related coverage on daily.dev._

### How did attackers hide malware inside a trojan delivered via a malicious Custom GPT?

An eight-stage infection chain used an MSI installer that abused a legitimately signed Canon binary (COTFileReadApp.exe) to sideload a patched malicious DLL. The loader itself was hidden inside a .wav audio file, and the final remote access trojan was unpacked from an encrypted archive named monitor.raw, then communicated with its command-and-control server over DNS-over-HTTPS while persisting via a Run key and scheduled task both named 'Canon Configuration Reader.'

_Anyone dissecting multi-stage malware loaders can compare notes on techniques like this via daily.dev._

### When is OpenAI retiring Custom GPTs?

OpenAI plans to retire Custom GPTs entirely on December 11. This comes after malicious Custom GPTs, including one called 'Plus 5.6,' were found being used to lure victims into a ClickFix malware campaign hosted directly on chatgpt.com, with one malicious listing removed by September 25 while a second variant of the same campaign remained live on September 27.

_Teams planning migrations away from deprecated features can track OpenAI platform changes on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@idoshamun** · 0 upvotes

> These guys always find the worst backdoors

## Similar posts on daily.dev

- [ChatGPT share links abused to host fake outage pages to deliver malware](https://daily.dev/posts/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware-h2gq8yzz2) · BleepingComputer · 1 upvotes · 0 comments
- [HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data Leakage](https://daily.dev/posts/hackedgpt-novel-ai-vulnerabilities-open-the-door-for-private-data-leakage-v1llnf112) · Security Boulevard · 0 upvotes · 0 comments
- [OpenAI ChatGPT fixes DNS data smuggling flaw](https://daily.dev/posts/openai-chatgpt-fixes-dns-data-smuggling-flaw-33yjya6he) · The Register · 1 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#chatgpt](https://daily.dev/tags/chatgpt)

[View this post on daily.dev](https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Attackers turned ChatGPT's own domain into a ClickFix lure","url":"https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs"},"datePublished":"2026-09-30T21:31:01.262Z","dateModified":"2026-09-30T21:31:41.195Z","description":"A remote access trojan campaign is abusing malicious Custom GPTs hosted directly on chatgpt.com, including one named 'Plus 5.6,' to lure victims through Google...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4bcacc1b5186b7a3ede43dd12e8f22a5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4bcacc1b5186b7a3ede43dd12e8f22a5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Trends","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Trends","logo":"https://media.daily.dev/image/upload/s--ZfSp3asX--/f_auto,q_auto/v1780996004/logos/trends?_a=BAMAMiWQ0","url":"https://daily.dev/sources/trends"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security,malware,chatgpt","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Trends","item":"https://daily.dev/sources/trends"},{"@type":"ListItem","position":3,"name":"Attackers turned ChatGPT's own domain into a ClickFix lure"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs","comment":[{"@type":"Comment","text":"These guys always find the worst backdoors","datePublished":"2026-10-01T05:05:16.579Z","url":"https://daily.dev/posts/pTODxRoFs#c-mXdcKNmla","author":{"@type":"Person","name":"Ido Shamun","url":"https://daily.dev/idoshamun","image":"https://media.daily.dev/image/upload/s---xy_OAwk--/f_auto,q_auto/v1703781380/avatars/avatar_28849d86070e4c099c877ab6837c61f0"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/attackers-turned-chatgpt-s-own-domain-into-a-clickfix-lure-ptodxrofs#faq","mainEntity":[{"@type":"Question","name":"What is the ClickFix attack technique and how does it trick users into running malware?","acceptedAnswer":{"@type":"Answer","text":"ClickFix is a social engineering technique where victims are shown a fake verification page, such as a spoofed Cloudflare CAPTCHA, that instructs them to paste and run a PowerShell command themselves to 'prove they are human.' In one campaign, victims reached this lure via malicious Custom GPTs hosted on chatgpt.com and promoted through Google Ads, meaning the malicious payload is self-executed by the victim rather than delivered directly. Security teams tracking emerging social-engineering tactics like this can follow related coverage on daily.dev."}},{"@type":"Question","name":"How did attackers hide malware inside a trojan delivered via a malicious Custom GPT?","acceptedAnswer":{"@type":"Answer","text":"An eight-stage infection chain used an MSI installer that abused a legitimately signed Canon binary (COTFileReadApp.exe) to sideload a patched malicious DLL. The loader itself was hidden inside a .wav audio file, and the final remote access trojan was unpacked from an encrypted archive named monitor.raw, then communicated with its command-and-control server over DNS-over-HTTPS while persisting via a Run key and scheduled task both named 'Canon Configuration Reader.' Anyone dissecting multi-stage malware loaders can compare notes on techniques like this via daily.dev."}},{"@type":"Question","name":"When is OpenAI retiring Custom GPTs?","acceptedAnswer":{"@type":"Answer","text":"OpenAI plans to retire Custom GPTs entirely on December 11. This comes after malicious Custom GPTs, including one called 'Plus 5.6,' were found being used to lure victims into a ClickFix malware campaign hosted directly on chatgpt.com, with one malicious listing removed by September 25 while a second variant of the same campaign remained live on September 27. Teams planning migrations away from deprecated features can track OpenAI platform changes on daily.dev."}}]}
```

