Hackers Target Claude AI with Infostealer Malware Attacks
The Claude AI platform from Anthropic is facing serious security threats as hackers exploit infostealer

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.
Huntress, which observed the activity in late September 2026, reported that this marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Previous campaigns have weaponized shared conversations with AI chatbots and malicious artifacts to distribute stealer malware and remote access trojans (RATs).
Custom GPTs refer to a personalized version of ChatGPT that allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. They are hosted on the legitimate ChatGPT website with the Custom GPT name at the top.
In the incidents observed, victims interacted with an attacker-created Custom GPT, which was programmed to respond to their prompts with a message that included a Google Sites link. This link led them to a ClickFix-style attack, which resulted in the download and execution of a malicious MSI installer.
The installer initiates a DLL sideloading chain responsible for loading shellcode, which is used to launch a persistence script and a RAT payload. At least 40 users have been infected as part of this campaign.
The attack begins with a sponsored result for searches like "chatgpt" on Google. Users who interact with the Custom GPT named "Plus 5.6" receive a "Service Availability Notice" instructing them to either upgrade their subscription tier or navigate to a backup Google Sites domain due to "limited availability on the primary domain." To encourage users to opt for the latter, the notice suggests using the backup domain for immediate access.
If victims follow through, they are presented with a fake Cloudflare CAPTCHA check that triggers a ClickFix attack, deceiving them into executing a malicious PowerShell command. This command deploys an MSI installer that abuses a legitimate Canon-signed binary to sideload a rogue DLL.
The DLL is an altered version of a real Canon DLL that loads a second, unsigned DLL, which extracts an encrypted loader from a .WAV audio file. This tactic of hiding payloads within audio and video file formats has been previously observed.
In the final stage, the loader shellcode unpacks the trojan and a persistence script from an encrypted file system, bypassing security measures and running anti-virtual machine checks. The trojan supports various features, including capturing camera input and system audio, running remote desktop sessions, and searching file contents across the system.
Huntress noted that the RAT uses DNS-over-HTTPS to find its command and control server, which is hidden in encrypted form within the code. The malware has been found to drop a legitimately signed binary that launches Google Chrome with a temporary browser profile.
Overall, this incident highlights how threat actors are turning trusted platforms into convincing entry points for social engineering, whether through ChatGPT's Custom GPT feature or Google Sites for hosting ClickFix attacks.