Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

A new cybersecurity campaign is exploiting the popularity of OpenAI's custom GPTs to distribute Remote Access Trojans (RATs). Threat actors are leveraging legitimate domains associated with OpenAI and Google to create convincing lures that trick users into downloading malicious payloads. This technique, described as a 'ClickFix' style attack, relies on social engineering to bypass standard security filters by masquerading as helpful AI tools. Once a user interacts with these malicious GPTs, they are prompted to perform actions that lead to the execution of malware, granting attackers unauthorized access to their systems. Security researchers warn that as the ecosystem of custom AI agents grows, users must exercise extreme caution when interacting with third-party GPTs. This incident highlights the evolving nature of AI-based threats, where attackers repurpose trusted platforms to facilitate sophisticated phishing and malware delivery campaigns.
This is a summary. Read the full article at the original source:
Dark ReadingRelated stories
Microsoft has issued a warning regarding a critical vulnerability, tracked as CVE-2026-73570, affecting the Zimbra Collaboration Suite. The flaw allow…
Hackers steal millions of U.S. military personnel records in months-long breach
The U.S. Department of Defense has officially confirmed a significant data breach involving the personal information of millions of current and former…
Good Bear 1.0: Isolated Trust for Russian PKI, Interface, Licensing, and Build
The release of Good Bear 1.0 has been announced, a specialized open-source browser designed for secure access to websites utilizing Russian Ministry o…



