AI Cybersecurity Threats in 2026: Malicious Custom ChatGPTs Emerge
Threat actors are constantly iterating on delivery vectors, turning trusted developer features and advertising channels into weapons against enterprise and consumer users alike. In late September 2026, managed detection and response (MDR) researchers at Huntress uncovered a sophisticated campaign abusing sponsored Google search results to promote fraudulent custom variants of OpenAI’s ChatGPT. These malicious models directed unsuspecting targets to external staging sites, where classic social engineering and ClickFix tactics executed remote access trojans (RATs) directly on local endpoints.
This incident highlights a critical inflection point in modern AI cybersecurity threats. By leveraging legitimate hosting domains like chatgpt.com for malicious instructions, attackers bypass standard domain reputation checks and exploit the inherent trust users place in artificial intelligence tools. Security teams must adapt their incident response playbooks and endpoint monitoring strategies to account for threat actors weaponizing AI agent ecosystems.
Leveraging Google Sponsored Ads and Official OpenAI Infrastructure
The infection vector begins with malicious or compromised search ads appearing prominently in Google search results for popular AI queries. Unsuspecting users seeking advanced AI utility click the sponsored link, which leads them straight to a custom ChatGPT variant hosted on OpenAI's official infrastructure. OpenAI's platform allows creators to bundle custom instructions, extra knowledge bases, and specialized skills into tailored GPT instances.
In this campaign, researchers identified a malicious model dubbed 'Plus 5.6'. While OpenAI scheduled the broader retirement of custom GPTs for December 2026, attackers rapidly spun up and rotated these models before moderation could intervene. Once a user engaged with the 'Plus 5.6' GPT, the model provided crafted instructions directing them away from the platform to an external backup page hosted on Google Sites.
Relying on legitimate domains for both the AI instructions and secondary hosting creates a formidable optical illusion. Users who inspect URLs out of habit see official brand domains, lowering their guard against subsequent prompts.
The ClickFix Social Engineering and PowerShell Execution Chain
Upon arriving at the Google Sites landing page, visitors encountered a deceptive interface featuring a fake Cloudflare verification check. This classic ClickFix ruse falsely claimed that the user's browser or session required manual validation before accessing the requested AI content.
The fake verification instructions directed the victim to copy a PowerShell command to their clipboard and execute it via the Windows Run dialog or PowerShell console. When executed, this command initiated a silent multi-stage infection chain:
- MSI Installer: A malicious Microsoft Installer (.msi) package is pulled down from temporary directories.
- Side-Loading Execution: The installer launches a legitimate, signed application (initially signed by Canon, and later updated to use Stardock-signed binaries) alongside a modified DLL.
- Malware Loading: The benign executable side-loads the malicious DLL, executing the payload in memory without triggering immediate security alerts.
Huntress researchers noted that while they tracked dozens of connections to the Google Sites staging assets, actual deployment via custom GPT instructions accounted for confirmed initial compromises, underscoring how targeted AI channels achieve high conversion rates for threat actors.
Advanced RAT Capabilities and Encrypted Storage Mechanics
The payload deployed in this campaign is a fully featured remote access trojan equipped with extensive surveillance and control capabilities. Once active on a compromised host, the RAT provides threat actors with:
- Remote desktop access for real-time interaction.
- Audio and camera capture capabilities for persistent espionage.
- Comprehensive host reconnaissance and automated file searches.
- The ability to download and execute secondary payloads on demand.
To ensure persistence across reboots, the malware establishes two persistence mechanisms: a new Windows Registry Run key and a scheduled task, both cleverly masked under the innocuous-sounding label 'Canon Configuration Reader.'
Furthermore, researchers highlighted Phase 6 of the attack chain, where attackers abandoned simple encrypted blobs in favor of a custom encrypted archive file system. Operating much like a homemade encrypted ZIP file, this structure begins with a small header followed by an index of over 1,100 indexed entries—each recording its parent directory, individual file size, and a unique per-file decryption key. This bespoke obfuscation strategy allows the malware to conceal its persistence scripts and modules entirely within memory or benign-looking file directories.
Securing Agentic Workflows Against Modern AI Cybersecurity Threats
As organizations accelerate AI adoption in 2026, securing agentic workflows requires moving beyond perimeter defenses and signature-based scanning. Threat actors will continue exploiting trust in AI platforms and search ad networks until comprehensive validation and hardening standards are universally enforced.
To defend against ClickFix and AI-driven malware delivery vectors, security leaders and system administrators should implement the following practices:
- Process Activity Monitoring: Monitor endpoint telemetry for anomalous process chains, such as PowerShell spawning
msiexec.exesilently from temporary user folders (%TEMP%or%LOCALAPPDATA%). - Application Control and Integrity: Restrict binary side-loading by auditing signed applications executing from non-standard program directories.
- Behavioral Detection Rules: Establish detection alerts for recurring scheduled tasks and registry Run keys with suspicious naming conventions like 'Canon Configuration Reader.'
- User Education on Social Engineering: Train employees and users to recognize ClickFix prompts, fake security verifications, and anomalous redirects originating from sponsored search results or third-party AI assistants.
By combining rigorous endpoint visibility with proactive threat intelligence, security operations centers (SOCs) can intercept multi-stage infection chains before remote access trojans establish a permanent foothold in the corporate environment.