Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Via ClickFix Lures
Threat actors are abusing ChatGPT's Custom GPT feature to trick users into visiting malicious sites that deploy ClickFix lures, leading to the download of a remote access trojan (RAT). The attack starts with sponsored search results directing victims to attacker-created Custom GPTs, which provide links to fake Cloudflare CAPTCHA pages that execute PowerShell commands to install malware using DLL sideloading and evasion techniques. Over 40 users have been infected so far in this campaign, highlighting continued exploitation of trusted AI platforms for social engineering and malware delivery.
https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html














