Malicious Custom GPTs Used as RAT Delivery Lure in ClickFix-Style Campaign
Threat actors abuse OpenAI and Google domains to distribute malware under the guise of AI functionality

Key Takeaways
- Threat actors are abusing OpenAI Custom GPTs and Google domains to deliver malware via social engineering.
- The campaign mimics ClickFix-style tactics, tricking users into executing commands that deploy RATs and other payloads.
- No CVE or zero-day vulnerability is involved; the attack depends on user interaction and trust in legitimate services.
Related Security News

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver Remote Access Trojans (RATs). Huntress observed the activity in late September 2026, marking another instance of abuse in trusted artificial intelligence platforms. The campaign directs victims from AI-generated content to external sites using ClickFix social engineering lures that trick users into executing commands that deliver malware.




