Threat actors are exploiting ChatGPT Custom GPTs to impersonate legitimate services and redirect victims to ClickFix malware lures that deliver remote access trojans. Huntress observed the campaign in late September 2026, with over 40 users infected through malicious MSI installers that abuse legitimate binaries for DLL sideloading. The attack chain uses encrypted payloads hidden in audio files and implements anti-analysis techniques including AMSI bypass and virtual machine detection.