MalwareSep 30, 2026
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Malicious custom GPTs are being used to deliver malware via lures on OpenAI and Google domains.
Summary
Threat actors are leveraging custom GPTs within ChatGPT to distribute malware, mimicking tactics seen in previous campaigns like ClickFix. These malicious GPTs use legitimate domains from OpenAI and Google as lures to trick users into downloading malicious payloads, effectively turning the AI platform into a vector for Remote Access Trojan (RAT) delivery.
Entities
ChatGPT (product)OpenAI (vendor)Google (vendor)ClickFix (campaign)