Malicious Custom GPTs steer users into remote access malware
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, October 5th, 2026.
Users searching for AI services can be manipulated into installing remote access malware themselves. In this campaign, attackers used sponsored search results, a malicious Custom GPT, a fake service notice, and a counterfeit CAPTCHA. Victims were then instructed to paste an obfuscated PowerShell command. The chain installed an MSI and established persistence for a remote access trojan. At least 40 incidents were linked to the campaign’s Google Sites infrastructure, including two infections traced to malicious Custom GPTs.
The attack borrows trust from familiar AI and CAPTCHA experiences while shifting the final execution step to the user. It also uses signed software and in-memory techniques to make detection harder.
For leaders, a legitimate and trusted platform can still host the first step of a social-engineering chain. For defenders, hunt for PowerShell launching msiexec, signed binaries running from unusual user-profile paths, suspicious adjacent DLLs, and unexpected scheduled tasks. The larger lesson is that any request to paste a command crosses a security boundary, regardless of which website presents it. Block command-pasting instructions in user guidance and investigate PowerShell activity connected to AI-service or CAPTCHA workflows.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.