Malicious Custom GPT on chatgpt.com lures users into installing a RAT A malicious ChatGPT Custom GPT named "Plus 5.6" is being promoted through sponsored Google results to redirect users to a fake Cloudflare CAPTCHA page that installs a remote access trojan (RAT), according to Huntress. The Huntress SOC has responded to at least 40 incidents tied to the specific Google Sites domain used in the campaign, and confirmed two of those incidents involved the RAT payload. Malware peddlers are using sponsored Google results to push a malicious ChatGPT Custom GPT named “Plus 5.6,” created to lead users to a fake Cloudflare CAPTCHA check and, ultimately, make them download and run a remote access trojan RAT . “The campaign has impacted dozens of users: the Huntress SOC has responded to at least 40 incidents stemming from the specific Google Sites domain involved in this attack, and confirmed that two of these incidents came … More https://www.helpnetsecurity.com/2026/09/29/malicious-chatgpt-custom-gpt-malware-via-clickfix/ The post Malicious Custom GPT on chatgpt.com lures users into installing a RAT https://www.helpnetsecurity.com/2026/09/29/malicious-chatgpt-custom-gpt-malware-via-clickfix/ appeared first on Help Net Security https://www.helpnetsecurity.com .