Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Huntress reports threat actors weaponizing AI-powered chatbots to distribute Remote Access Trojans

Key Takeaways
- Threat actors are abusing ChatGPT Custom GPTs to distribute malware via ClickFix lures.
- Huntress observed the campaign in late September 2026.
- Malicious GPTs disguise themselves as legitimate product offerings to direct victims to harmful sites.
- ClickFix lures trick users into executing commands that deliver Remote Access Trojans (RATs).
Related Security News

Attackers Abuse MSP360 RMM to Deploy ScreenConnect in Dual-RMM Phishing Campaigns
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. Once executed, the legitimate MSP360 installer establishes remote management access on affected endpoints, and ScreenConnect is subsequently deployed to provide dual-RMM persistence. The campaigns leverage deceptive file names and social-engineering themes to trick users into executing the installer. No zero-day vulnerabilities are exploited; the attack relies on user execution. Microsoft and MSP360 advise user vigilance, email filtering, and verifying software sources, and recommend keeping MSP360 and ScreenConnect updated to the latest versions.




