Malicious Custom GPTs Use Google Ads to Distribute Remote Access Trojans

Cybercriminals are weaponizing the reputation of OpenAI’s ChatGPT and Google Search ads to distribute Remote Access Trojans (RATs). By leveraging malicious Custom GPTs, attackers are successfully tricking users into manually bypassing their own system security to install malware.

The campaign begins with sponsored Google Search results for “ChatGPT,” which redirect unsuspecting users to malicious Custom GPTs hosted on OpenAI’s platform. One specifically identified GPT, titled “Plus 5.6” and attributed to a “community builder,” served as a primary lure in recent attacks. OpenAI responded by removing the identified malicious GPTs on September 25 and September 27, 2026, following reports of the activity.

Conceptual visualization of a user-initiated command bypassing a security shield.
The maneuver relies on users manually executing code that evades automated defenses.

The Social Engineering Loophole

The core of the maneuver is a psychological trick that replaces technical exploits with human-assisted execution. Once a user interacts with the malicious GPT, they are eventually directed to a Google Sites domain designed to mimic a legitimate Cloudflare CAPTCHA verification page.

When the user attempts to complete the “verification,” the site claims an error has occurred and provides a “fix.” The infection chain is triggered when a user follows instructions on the fake Cloudflare CAPTCHA check page.

According to research from Huntress, security analysts have responded to at least 40 separate incidents stemming from the specific Google Sites domain involved in this campaign. The scale of the operation suggests that attackers are finding success by hiding within the ecosystem of trusted tools like Google Ads and ChatGPT.

Advanced Evasion via DLL Sideloading

The malware delivery mechanism is notably sophisticated, utilizing a technique known as DLL sideloading to minimize the footprint of the attack. Once the infection chain is triggered, the campaign delivers a payload that includes legitimately signed executables from well-known vendors, such as Canon and Stardock.

Because these executables carry valid digital signatures, they are less likely to trigger security warnings. However, the attackers pair these legitimate files with a malicious Dynamic Link Library (DLL). When the signed executable runs, it automatically loads the malicious DLL, granting the Remote Access Trojan persistence and control over the infected machine without needing to exploit a software vulnerability.

This “weaponization of trust” exploits the fact that most users are conditioned to trust the interfaces of major platforms. By the time a user realizes the “verification” process is unusual, they have already manually invited the RAT into their system, providing attackers with a foothold for data theft or further network penetration.

More From Category

More Stories Today