Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Overview
Cybercriminals are exploiting ChatGPT's Custom GPTs feature to trick users into visiting harmful websites. These sites use ClickFix lures to deliver Remote Access Trojans (RATs), which can take control of victims' devices. This tactic was observed by Huntress in late September 2026 and represents a concerning trend where trusted AI platforms are manipulated to spread malware. Users who interact with these malicious GPTs may unknowingly expose their systems to significant risks. This incident serves as a reminder for individuals and organizations to be cautious when engaging with AI-driven tools and to verify the legitimacy of any offerings before clicking links.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: ChatGPT Custom GPTs, malicious websites employing ClickFix lures.
- Action Required: Users should avoid clicking on links from unknown or suspicious sources, and organizations should educate employees on identifying potential phishing and malware threats.
- Timeline: Ongoing since late September 2026
Original Article Summary
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
Impact
ChatGPT Custom GPTs, malicious websites employing ClickFix lures.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since late September 2026
Remediation
Users should avoid clicking on links from unknown or suspicious sources, and organizations should educate employees on identifying potential phishing and malware threats.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Phishing, Malware.