Back to all lessons
Awareness Lessons
last week

Malicious Custom GPTs Used to Deliver Remote Access Trojans

Threat actors are abusing OpenAI's custom GPT functionality to craft convincing AI-powered lures that redirect users to malicious payloads, including Remote Access Trojans (RATs). By piggybacking on trusted domains from OpenAI and Google, attackers exploit the inherent trust users place in well-known platforms, making detection significantly harder. This mirrors social engineering tactics from campaigns like ClickFix, demonstrating how emerging AI tools rapidly become new attack surfaces. The core failure is a lack of user awareness around AI platform misuse combined with insufficient vetting controls for third-party custom GPTs. As AI adoption accelerates, organizations that do not educate users about AI-specific threat vectors will face increasing exposure.

Tactical Insight

Immediate actions

  • Block or restrict access to unapproved custom GPT integrations via web filtering or endpoint controls until organizational risk can be assessed.
  • Issue an urgent security awareness advisory to all staff warning about malicious AI lures mimicking legitimate domains.

Long-term improvements

  • Establish an approved-list policy for AI tools and custom GPT usage, requiring security review before organizational adoption.
  • Integrate AI platform threat scenarios into annual security awareness training to keep users informed of evolving social engineering tactics.
  • Implement application whitelisting on endpoints to prevent unauthorized executables, including RAT payloads, from running.

Detection measures

  • Deploy endpoint detection and response (EDR) solutions configured to alert on behaviors consistent with RAT installation, such as unexpected outbound connections or new persistence mechanisms.
  • Monitor network traffic for anomalous connections to newly registered or suspicious domains following user interactions with AI platforms.
  • Enable logging and SIEM alerting for executable downloads originating from browser sessions on AI-related domains.