
Malicious Custom GPTs Used as RAT Delivery Lure in ClickFix-Style Campaign
Security researchers report a campaign in which threat actors create and promote malicious Custom GPTs on the OpenAI platform, using legitimate Google domains as lures. The social engineering approach mimics ClickFix tactics, persuading users to execute commands that deploy remote access trojans (RATs) or other malware. No specific CVE or zero-day vulnerability has been identified; the attack relies on user interaction and trust in legitimate AI services.




