1. Basic Information
- Original Title: How threat actors are turning trusted AI platforms into an attack surface
- Sources: BleepingComputer, Huntress, ADAMnetworks
- Published: 2026-09-11
- Updated: 2026-09-30
- Severity: High
- Basis for Severity: Legitimate AI sharing pages have been weaponized for malvertising and SEO-driven malware distribution, with infections confirmed across multiple organizations. This technique exploits trust in public pages.
- Original Article: How threat actors are turning trusted AI platforms into an attack surface
- Related Sources: Huntress: FakeAgent malvertising, Huntress: MacSync stealer and RAT, Huntress: What is AI poisoning?, Huntress: AMOS AI share chat abuse, MITRE ATT&CK: Malicious Copy and Paste, BleepingComputer: Hackers hijack HBO Max Reddit account to push malware in ClickFix ads, ADAMnetworks: HBO Max Ads Exposed the PasteSwitch ClickFix Operation, Kaspersky: MacSync under the microscope: new delivery methods and a new payload, BleepingComputer: MacSync malware uses iCloud Calendar events, Huntress: Custom GPT ClickFix RAT, BleepingComputer: Custom GPT RAT campaign, Dark Reading: malicious Custom GPTs
- Related Malware: FakeAgent, SectopRAT, MacSync, AMOS, PasteSwitch, Amatera, Custom GPT ClickFix RAT
- Affected Products: Claude Artifacts, Claude Share, ChatGPT shared conversations, ChatGPT Custom GPTs, Google Sites, Canon CaptureOnTouch, Stardock DeElevate, macOS, Windows, Reddit Ads, HBO Max
Update Reason: Added the Custom GPT ClickFix/RAT chain, 40 related incidents with 2 confirmed Custom GPT cases, Canon/Stardock variants, persistence, RAT capabilities, and detection information.
Key Update (2026-10-01): Added an attack chain that starts from the ChatGPT Custom GPT "Plus 5.6", redirects to a Google Sites ClickFix page, and executes a RAT via DLL sideloading using Canon/Stardock signed binaries. Of the 40 related incidents tracked by Huntress, 2 have been confirmed to originate from Custom GPTs.
2. Executive Summary
Legitimate AI sharing pages and malvertising on a compromised official HBO Max Reddit account were abused to trick users into downloading fake applications or executing terminal commands. The macOS ad campaign by HBO Max and the Windows PasteSwitch delivery path identified in related research are treated separately.
3. Attack Flow
1. FakeAgent: Delivering SectopRAT to Windows
- Users are directed from Bing sponsored ads to a legitimate Claude Artifact.
- A download link within the Claude Artifact redirects users to an external fake Claude Desktop distribution site.
- The user executes
ClaudeDesktop.exe. - SectopRAT is launched through signed-helper DLL sideloading, a scheduled task, virtual environment detection, and EtherHiding.
- SectopRAT provides remote management capabilities.
2. MacSync: macOS Infection via Claude Shared Conversations
- Users are directed from Google sponsored ads to fake Apple Support instructions on Claude Share.
- The user opens the Terminal and pastes and executes the instructed curl command.
- A six-stage setup deploys a loader, an AppleScript-based info stealer, and a Mach-O RAT.
- The malware collects browser cookies and credentials, Keychain items, SSH and cloud authentication keys, and cryptocurrency wallet data.
- It also uses a signed helper with screen recording permissions and a modified wallet app designed to steal recovery phrases.
3. AMOS: Fake Disk Cleanup Instructions on ChatGPT and Grok
- Shared ChatGPT and Grok conversations appearing in search results pose as instructions to free up macOS disk space.
- The user pastes and executes a command in the Terminal to retrieve a loader.
- Credentials obtained via a fake password prompt are verified and used for privilege escalation and data theft.
- AMOS collects and exfiltrates browser, Keychain, and wallet data, while replacing select wallet apps with modified versions.
- Persistence is established using a LaunchDaemon and a monitoring script to restart the data theft program.
4. PasteSwitch: macOS Targeting via Ads on the Official HBO Max Reddit Account
- A compromised official HBO Max Reddit account delivered 108 malicious ads over approximately 48 hours.
- The ads directed users to pages for fake HBO Max apps and similar tools, prompting macOS users to paste and execute commands in the Terminal.
- At the time researchers investigated, the HBO Max ad delivery had ceased; technical investigation into the delivery infrastructure proceeded using execution commands targeting a related fake Alfred page.
5. PasteSwitch: macOS Info Stealing and Windows Amatera Delivery Identified in Related Research
- ADAMnetworks tracked fake app landing pages and related infrastructure to map out delivery chains spanning multiple operating systems and timeframes.
- The MacSync path was observed collecting credentials and other data into
/tmp/osalogging.zip, which was then exfiltrated via HTTP PUT in approximately 10MB chunks. - Another fake Claude page displayed commands utilizing
mshtafor Windows targets, launching PowerShell from a file treated as both an MP3 and an HTA. - The Windows path executes Amatera via scheduled tasks, AMSI bypass, and in-memory loading. This path is not treated as part of the infection chain confirmed in the 108 HBO Max ads.
6. Alternative MacSync Vector: Distribution via iCloud Calendar Events (Added 2026-09-24)
- In an alternative vector analyzed by Kaspersky, users download a fake app DMG and run it to launch an initial loader. This does not follow the same sequential flow as previously reported Claude shared conversation or manual paste vectors.
- At least one sample retrieved public iCloud Calendar content, passed it to zsh, and executed instructions embedded in the description field. Other samples utilized different retrieval sources, meaning this is not a shared vector across all infections.
- Subsequent stages include a Swift-based info stealer and an Objective-C backdoor disguised as Finder. Persistence mechanisms utilizing LaunchAgents,
.zshrc, and global Git hooks were also identified. - Browser extension distribution and Ledger-related instruction names were also analyzed, but since certain scripts could not be retrieved by researchers, the exact operation of every feature and its execution in victim environments have not been uniformly confirmed.
There are no reports of vulnerabilities in Calendar or iCloud being exploited. Instead, the loader executed after running the fake application treats content hosted on legitimate services as execution instructions.
7. Transition from Custom GPT "Plus 5.6" to ClickFix and RAT (Added 2026-10-01)
- Users are directed from Google sponsored search results to an attacker-created Custom GPT named "Plus 5.6" hosted on legitimate
chatgpt.com. - The Custom GPT returns a service availability notice, redirecting the user to a "backup domain" on Google Sites. The landing page displays a fake Cloudflare CAPTCHA and prompts the user to paste and execute a PowerShell command.
- PowerShell retrieves an obfuscated script and an MSI from a decimal IP address, executing a silent install via
msiexec /qn /norestart. - The first variant performs DLL sideloading using the Canon-signed
COTFileReadApp.exeand a patchedceiinfolog.dll; the second variant uses the Stardock-signedDeElevate64.exeand a patchedDeElevator64.dll. - An encrypted loader is hidden within a WAV file or a NuGet package, establishing dual persistence via Run keys and scheduled tasks before executing the RAT in memory.
- The RAT features screen, camera, and microphone capture, 17 browser targets, file search, host discovery, follow-on payload execution, and C2 capabilities over DNS-over-HTTPS. The 40 incidents verified by Huntress are associated with the same Google Sites domain, with 2 confirmed to originate from Custom GPTs.
4. Attacker Positioning and Execution Location
- External threat actors direct users via ads, search results, and public AI sharing pages.
- Once executed, the RAT/info-stealing malware accesses credentials and wallets directly on the victim's endpoint.
5. Victim and Administrator Perspectives
Victim Perspective
- Pages disguised as Claude Desktop, Apple Support, or macOS disk cleanup tools, prompting manual command execution in the Terminal.
- Fake applications and unexpected Full Disk Access or screen recording prompts.
Administrator Perspective
- User-initiated Terminal or shell execution, suspicious curl traffic, unknown executables, DLL sideloading, and scheduled tasks. The shell parent process is not necessarily a browser.
- New external domains visited immediately following visits to legitimate AI domains, along with data access targeting wallets, the Keychain, and browsers.
6. Success and Failure Conditions
Success Conditions
- The user trusts search ads, AI sharing pages, or compromised official social media account ads, and executes fake apps or instructed commands. AI sharing pages are not a mandatory condition for all vectors.
- Execution of external downloads or clipboard-delivered shell commands.
- Application control or EDR fail to block multi-stage loaders, sideloading, or credential access.
Failure Conditions and Risk Mitigation
- Inference: Inspect redirection destinations and downloads originating from sharing pages, blocking them if identified as malicious.
- Inference: Control unauthorized script execution on endpoints to counter vectors where users paste commands from sharing pages. Restricting browser child processes alone is insufficient to prevent this entire vector.
- Inference: Application control or EDR that blocks unauthorized DLL loading, persistence mechanisms, and credential access can limit subsequent damage.
7. Impact Upon Successful Exploitation
- RAT infection and remote management of Windows and macOS endpoints.
- Theft of browser cookies and credentials, Keychain items, SSH and cloud authentication keys, and cryptocurrency wallet data.
- Inference: If stolen sessions or keys are valid, this may lead to unauthorized access to SaaS and cloud environments or cryptocurrency theft.
8. Observable Logs
Inference: Depending on logging configurations, the following records can be used for internal investigations:
- Primary delivery relies on search ads, SEO, or compromised social media account ads; no delivery via email has been reported.
Proxy, SWG, and DNS
- Inference: Examine records of navigation from AI sharing pages or Reddit ads to external fake app pages, as well as connections to payloads and C2 servers. Browsing AI sharing pages should not be treated as a strict prerequisite for all vectors.
Endpoint and EDR
- Inference: Depending on EDR log coverage, user-launched shells and curl commands, DLL loading events, scheduled tasks, and access to credential files can be identified. A direct parent-child relationship between the browser and the shell should not be assumed.
Authentication and IdP
- Inference: Usage of stolen cookies, cloud auth keys, or SSH keys from unknown sources.
SaaS and Cloud
- Inference: If stolen tokens are abused, review SaaS and cloud audit logs to identify usage origins and targeted resources. AI sharing page navigation paths can be investigated via browser history or proxy logs where available.
Network
- Inference: C2 traffic for SectopRAT, MacSync, and AMOS; references to smart contracts used in EtherHiding; and anomalous high-volume credential exfiltration.
- Inference: In the PasteSwitch MacSync path, if HTTP logs are available, examine chunked PUT transmissions alongside
upload_id,chunk_index, andtotal_chunks. In encrypted traffic, destination and volume alone cannot confirm data theft.
Artifacts to Verify in Custom GPT / ClickFix Chains
-
Proxy / Browser: Check for connections to
chatgpt.com/g/containing Google Ads tracking,sites.google.com/view/antibot172881, and the decimal IP1614733393. -
Endpoint / EDR: Verify PowerShell executing
msiexec,COTFileReadApp.exeorDeElevate64.exeunder%LOCALAPPDATA%\Programs\, and Run keys and scheduled tasks associated withCanon Configuration ReaderorStardock DeElevation Tool. - Network: Distinguish legitimate DNS-over-HTTPS queries to Cloudflare, Google, or Quad9 by correlating them with preceding ClickFix, MSI, and sideloading sequences.
9. Attack Success Assessment
Scope Confirmable via Public Information
- User Action Confirmed: Public Info: Huntress reports user execution of commands in fake Claude Desktop execution as well as MacSync and AMOS incidents. These three separate incidents are not treated as a single victim's continuous actions.
- Malware Execution or Auth Success Confirmed: Public Info: SectopRAT infections via FakeAgent, MacSync infostealing capabilities and RATs, and AMOS execution and persistence have each been reported.
- Data Theft or Session Compromise Confirmed: Public Info: Huntress reports data theft and analyzes collection targets for each malware family. This does not imply that all categories of sensitive data were stolen from every victim endpoint.
- Data Theft or Session Compromise Confirmed: Public Info: ADAMnetworks analyzed MacSync and Amatera collection and exfiltration processes during PasteSwitch-related research. This does not indicate the total volume of infections or data theft resulting from the 108 HBO Max ads.
Internal Assessment Criteria
- Subsequent Compromise Confirmed: Criteria: Confirmed unauthorized use of stolen sessions and authentication keys or unauthorized fund transfers. The scope of such success cannot be determined solely from the materials in this article.
10. Investigation Playbook
Inference: The following is an internal investigation procedure based on publicly available information:
Investigation Starting Point
- Initiate investigations upon observing suspicious external redirection from AI sharing pages or Reddit ads, user-executed commands, or unknown application execution.
Initial Verification
- Preserve the posting identity of ads and posts, source and destination URLs, retrieved files, and executed commands with timestamps. Distinguish between the macOS HBO Max ad vector and the Windows vector associated with related pages.
Endpoints and Servers
- For Windows, verify DLL sideloading, scheduled tasks, and RAT artifacts. For macOS, check shell history, quarantine attributes, LaunchAgents, LaunchDaemons, AppleScripts, TCC permissions, and modified wallet applications.
- For PasteSwitch, investigate
/tmp/osalogging.zipon macOS, andmshta, PowerShell, and scheduled tasks on Windows, according to the verified path. A direct browser-to-shell parent-child relationship is not a mandatory condition.
Authentication and Cloud
- Check browser sessions, SSH/cloud authentication keys, Telegram data, cryptocurrency wallets, and IdP logs for unknown usage origins and token creation events.
Subsequent Actions
- Check for the reuse of stolen cookies, cloud API enumeration, cryptocurrency wallet transfers, and the presence of additional RATs or remote management tools.
Containment
- Isolate endpoints to preserve evidence, revoke compromised browser and IdP sessions, and invalidate exposed tokens. Reissue SSH and cloud authentication keys, and if wallet recovery information was exposed, migrate assets to a newly created wallet generated on a secure device.
- Add malicious sharing URLs, redirection domains, and file hashes to internal blocking lists.
Decision Categories
- Categorize events into page visits, user execution, loader success, RAT/info-stealer C2, sensitive data theft, and subsequent abuse.
11. Defense and Detection Ideas
Inference: The following are proposed detection and mitigation strategies based on public information:
Single Events
- Inference: Treat suspicious retrieval and execution commands run within user-launched Terminal, PowerShell, or cmd instances as detection candidates. A direct browser child process requirement is not enforced.
- Inference: Monitor instances where signed helper binaries load unknown DLLs from the same directory, in conjunction with file provenance data.
Timeline Correlation
- Inference: Correlate visits to AI sharing pages or social media ads by the same endpoint/user with subsequent external redirections, app launches, shell executions, and credential access, maintaining path-specific branching.
Threat Hunting
- Inference: Conduct broad searches for commands, downloads, DNS queries, and credential access executed immediately before or after visits to suspicious sharing URLs, ads, or redirection targets. Widen initial search windows based on execution delays and log retention policies.
- Inference: For alternative vectors, correlate suspicious DMG/app execution with Calendar event retrieval, zsh execution, Finder-mimicking processes, and modifications to LaunchAgents,
.zshrc, or global Git hooks. Legitimate Calendar access alone must not be classified as malicious.
Log Gaps and Limitations
- In the absence of complete URLs, redirection chains, clipboard data, process parent-child relationships, and TCC history, distinguishing legitimate AI usage from attack vectors can be challenging.
Prioritized Mitigations
- Inference: Prioritize correlating page views with manual shell execution, enforcing application control, inspecting external redirection targets, and executing credential revocation procedures.
Behavioral Detection for Custom GPT Vectors
- Detect sequences where PowerShell silently installs an MSI with a GUID-like filename, immediately followed by the execution of a signed application from
%LOCALAPPDATA%\Programs\. - Correlate behaviors where identically named Run keys and scheduled tasks are recreated within short timeframes.
- Avoid global blocking of Canon and Stardock signed binaries; evaluate them based on deployment paths, unsigned/patched DLLs, and parent processes.
12. Facts, Inference, and Hypothesis
Facts
- In FakeAgent, Bing sponsored ads directed users to legitimate Claude Artifacts, which then led to fake Claude Desktop distribution domains to deploy SectopRAT. Huntress confirmed activity across at least 29 organizations.
- FakeAgent combined DLL sideloading using a signed
jcef_helper.exeand a modifiedlibcef.dll, scheduled tasks masquerading asDockerDesktop.exe, VMProtect, GPU-based virtual environment detection, and EtherHiding via smart contracts on the BSC network. - MacSync directed users from Google sponsored ads to fake Apple Support instructions on
claude.ai/share, prompting them to paste a Terminal command containingcurl, which deployed a six-stage loader, an AppleScript-based infostealer, and a Mach-O RAT. - Huntress reported that MacSync collects browser cookies and credentials, Keychain items, Telegram data, SSH and cloud authentication keys, and cryptocurrency wallet data, and also utilizes a signed helper for screen recording permissions.
- Huntress reported an AMOS incident in December 2025 where ChatGPT and Grok shared conversations appearing in search results posed as disk cleanup instructions, tricking users into pasting and executing commands.
- Public information indicates no compromise of AI vendor infrastructure, instead abusing trust in legitimate hosts and brands.
- According to Hudson Rock and ADAMnetworks, a compromised official HBO Max Reddit account distributed 108 malicious ads over approximately 48 hours, directing macOS users to fake software landing pages.
- Ad destinations included domains such as
hbomaxx.app. Following the cessation of HBO Max ad delivery, ADAMnetworks pursued technical investigations starting from execution commands obtained from a related fake Alfred page. - MacSync analyzed during related research featured capabilities to harvest browser credentials and cookies, cryptocurrency wallets, Telegram data, Apple Notes, keychains, cloud credentials, and shell history, exfiltrating data via HTTP PUT in roughly 10MB chunks to
/tmp/osalogging.zip. - A Windows vector on a separate fake Claude page utilizes
mshta, PowerShell, and files interpretable as both MP3 and HTA to execute Amatera in memory via scheduled tasks and AMSI bypass. This vector was identified during broader PasteSwitch research. - On September 24, 2026, Kaspersky reported an alternative MacSync vector beginning with fake applications, featuring a Swift-based infostealer and an Objective-C backdoor. Certain samples execute public iCloud Calendar content via zsh. There are no reports of vulnerabilities in Calendar or iCloud being exploited.
- Huntress responded to at least 40 incidents associated with the same Google Sites domain, confirming 2 originated from Custom GPTs. Not all 40 incidents are treated as originating from Custom GPTs.
- Variant 1 utilized Canon-signed binaries and a patched logging DLL, while Variant 2 utilized Stardock-signed binaries and a patched DLL; the final RAT was identical. Dual persistence via Run keys and scheduled tasks was also confirmed.
- The RAT features screen, camera, and microphone capture, 17 browser targets, file search, follow-on payload execution, host discovery, and C2 capabilities via DNS-over-HTTPS.
- Huntress reported the initial Custom GPT to OpenAI and confirmed its takedown by September 25, but identified a new Custom GPT for the same campaign on September 27.
Inference
- Relying solely on URL reputation data that permits domains like
claude.aimay cause defenders to miss malicious content hosted on legitimate hosts and external redirections. - It is necessary to correlate external page navigation and manual script execution while distinguishing whether the source is a legitimate AI sharing page or a compromised social media account ad.
Hypothesis
No additional hypotheses. Unconfirmed items are documented under "Open Questions and Further Investigation."
13. MITRE ATT&CK Mapping
| ID | Technique | Confidence | Basis |
|---|---|---|---|
| T1189 | Drive-by Compromise | High | Users are directed from ads and SEO results to legitimate AI sharing pages and malicious sites. |
| T1204.002 | User Execution: Malicious File | High | In FakeAgent, users execute the payload distributed as a fake Claude Desktop app. |
| T1204.004 | User Execution: Malicious Copy and Paste | High | MacSync and AMOS delivery vectors prompt users to paste and execute commands in the Terminal. |
| T1574.001 | Hijack Execution Flow: DLL Search Order Hijacking | High | FakeAgent combines a signed helper binary with a modified libcef.dll. |
| T1053.005 | Scheduled Task/Job: Scheduled Task | High | Creates scheduled tasks masquerading as DockerDesktop.exe on Windows. |
| T1555.003 | Credentials from Password Stores: Credentials from Web Browsers | High | MacSync and AMOS harvest browser cookies and credentials. |
| T1586.001 | Compromise Accounts: Social Media Accounts | High | The official HBO Max Reddit account was abused to distribute malicious ads. |
14. Open Questions and Further Investigation
- Complete inventories of malicious Claude Artifact/Share and ChatGPT/Grok shared URLs.
- Attribution of ad accounts and campaign operators.
- Lifespans and evolution of all C2 servers, contracts, and payload hashes for FakeAgent.
- Whether multiple campaigns share operators or automate AI sharing page creation remains unconfirmed.
- The compromise vector of the official HBO Max Reddit account and total infection counts stemming from the 108 ads.
- Infection volumes, operators, scope of Calendar abuse, and actual functionalities of unretrieved scripts for the newly reported MacSync vector.
- Builder identities, ad accounts, and the overall scale of delivery infrastructure for the "Plus 5.6" Custom GPT vector.
- Breakdown of initial access vectors other than Custom GPTs among the 40 related incidents.
- The final C2 address for the RAT has not been confirmed from recovered files and may be resolved at runtime or retrieved via encrypted settings.
15. Impact on SOCs and Organizations
Even when passing through legitimate AI sharing pages or official social media account ads, external download destinations and executed commands cannot be blindly trusted. Because a manually opened Terminal does not necessarily run as a browser child process, analysts must correlate user web browsing and script execution by timestamp. HBO Max ad incidents and alternative delivery vectors identified in related research must be distinguished within detection logic.
Because the Custom GPT vector leverages legitimate AI domains, Google Ads, Google Sites, and signed binaries sequentially, it bypasses allowlisting based solely on domain reputation or file signatures. Enterprise SOCs should not block AI service access outright, but instead monitor for the behavioral chain progressing from ads to Custom GPTs, external sites, ClickFix commands, silent MSIs, sideloading, and persistence.
16. Target Audience Summary
- SOC: Correlate external redirections from AI sharing pages or social media ads with subsequent application and Terminal execution, as well as credential access events per vector.
- Administrators: Avoid blanket allowances for AI sharing pages; implement application allowlisting, script execution controls, and monitoring that correlates browser browsing activity with shell execution.
- Users: Do not blindly execute suggested downloads or Terminal commands found in official account ads or AI responses; verify distribution sources and internal organizational procedures.
Top comments (0)