Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

Cyber Attackers Abusing ChatGPT Domain to Deliver Malicious Remote Access Trojans

A new wave of cyber attacks is exploiting the popularity of OpenAI’s ChatGPT, with threat actors creating malicious customized versions of the chatbot to trick users into downloading remote access Trojans (RATs). According to cybersecurity firm Huntress, this campaign has already affected dozens of users, who are lured in by fake instances of ChatGPT that appear to be legitimate but actually serve as a lure for malware.

The attackers create “Custom GPTs” that mimic the real product offerings of ChatGPT, including personal research assistants and HR knowledge bases. These Custom GPTs are then hosted on OpenAI’s trusted Web infrastructure, which is used to direct victims to malicious sites. Once on the site, users are presented with a prompt asking them to copy and paste system commands to “fix” a technical issue – a classic tactic known as ClickFix. This technique exploits trust in commercial software and human problem-solving tendencies.

The malware infection chain begins when a victim types any prompt into the Custom GPT. The output warns the user that the service is unavailable, but offers them an option to upgrade their subscription or use a “backup” domain hosted on Google Sites. Unbeknownst to the user, this link leads to a fake Cloudflare landing page with a CAPTCHA challenge, which ultimately delivers the ClickFix prompt.

The PowerShell command downloaded by the victim then executes a series of malicious actions. It downloads an MSI file, which abuses a legitimate Canon-signed application to sideload malicious DLLs. One of these DLLs extracts an encrypted loader hidden inside a WAV file, decrypts it, and executes it in memory. The loader then retrieves the RAT from a separate encrypted storage file, unpacks it, and deploys it on the victim’s machine.

The ultimate goal of this campaign is to deploy a RAT, which threat actors often use as a foothold into an organization’s environment. This can be used for data theft, extortion-based attacks, espionage, or other malicious activities. In some cases, the RAT has been observed pulling down additional payloads intended to steal browser data and map out the victim’s endpoint.

While Huntress was able to detect and isolate many of these attacks, the threat remains significant. “Left alone, though, this RAT is built to do three things: steal data, watch the people using the machine, and serve as a foothold into the rest of the network,” says Jonathan Semon, principal security operations analyst at Huntress.

So what can users and organizations do to protect themselves? For one, they should be extremely cautious when interacting with unfamiliar or customized versions of popular software like ChatGPT. Users should also keep their systems up-to-date and run regular security scans to detect any potential malware infections. Finally, staying informed about the latest threats and vulnerabilities is crucial in today’s rapidly evolving cybersecurity landscape. By being vigilant and proactive, we can reduce our exposure to these types of attacks and stay one step ahead of the threat actors.


Source: Dark Reading — 2026-09-30