Attackers Use Custom ChatGPT GPTs to Spread Remote-Access Malware
Security researchers have identified a campaign in which threat actors create malicious custom GPTs within ChatGPT and abuse legitimate OpenAI and Google domains to lure victims. The technique follows a ClickFix-style approach, tricking users into executing steps that ultimately deliver a remote access trojan (RAT) to their systems.
GoKawiil's interpretation of the reporting above, not reported fact.
By hosting malicious content on trusted domains like OpenAI's and Google's, attackers can bypass user suspicion and some security filters that flag unfamiliar URLs, according to researchers. This suggests a growing trend of abusing AI platforms' legitimacy to lower victims' guard, which could pressure AI companies to tighten vetting of custom tools built on their platforms.
- Threat actors are exploiting custom GPT features within ChatGPT to distribute malware.
- The campaign relies on ClickFix-style social engineering combined with trusted OpenAI and Google domains.
- The attack ultimately delivers a remote access trojan (RAT) to compromised systems.
YubiKey 5C NFC Security Key — With attackers increasingly abusing trusted platforms like ChatGPT and Google to trick users into running malicious payloads, hardware-based authentication is a strong defense layer for your accounts. A YubiKey adds phishing-resistant, two-factor protection that malware and social-engineering lures like ClickFix can't easily bypass.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: darkreading.com, 2026-09-30
Published there as: “Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.