Skip to main content
SecurityEnterprise

Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

Source: Dark Reading (opens in a new tab) · Alexander Culafi

Intel Summary

Dark Reading reports that threat actors are deploying malicious custom GPTs within ChatGPT and abusing legitimate domains from OpenAI and Google in a ClickFix-style campaign designed to lure users into downloading Remote Access Trojans (RATs).

Why It Matters

Exploiting trusted AI domains allows attackers to bypass reputation-based web filtering and deceive users. Enterprise defenders must account for ecosystem abuse in custom GPT marketplaces and reinforce defenses against social engineering tactics prompting local script execution.

Part of an ongoing development

Source

Threat actors deploy malicious custom GPTs on ChatGPT to distribute RATs

Dark Reading reports that threat actors are deploying malicious custom GPTs within ChatGPT and abusing legitimate domains from OpenAI and Google in a ClickFix-style campaign designed to lure users into downloading Remote Access Trojans (RATs). Claims are as reported; this summary makes no determination about accuracy or significance.

Organizations & Entities

Topics