Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

A New Twist on Old Tricks: ChatGPT Custom GPTs Used to Deliver RAT via ClickFix Lures

Attackers have found a new way to deliver malicious Remote Access Trojans (RAT) by exploiting vulnerabilities in custom-built Generative Pre-trained Transformers (GPT) models, specifically those created using the popular AI platform ChatGPT. These sophisticated phishing lures, known as “ClickFix,” have been used to trick victims into downloading and executing RATs on their devices.

The attackers’ modus operandi is straightforward: they create custom GPT models that mimic human-like conversations, often with a focus on helping users resolve technical issues or answering frequently asked questions. Once the victim interacts with the chatbot, the attacker injects malicious code, which is then executed by the user’s browser or device. The RAT allows the attacker to gain unauthorized access and control over the compromised system.

This campaign is particularly insidious because it leverages the trust users have in AI-powered tools like ChatGPT. Custom GPT models are designed to be flexible and adaptable, making them ideal for use in social engineering attacks. Attackers can create these fake chatbots quickly, allowing them to stay one step ahead of security teams.

What’s even more concerning is that this attack vector has the potential to affect anyone who interacts with online support services or uses AI-powered tools. The fact that attackers are exploiting vulnerabilities in custom GPT models highlights the importance of ensuring that AI systems are designed and implemented with security in mind from the outset.

As ChatGPT continues to grow in popularity, users must remain vigilant when interacting with online chatbots, especially those that claim to offer technical support or assistance with complex tasks. This attack serves as a stark reminder that even seemingly innocuous tools can be used for nefarious purposes if not properly secured.

To protect yourself from these types of attacks, always verify the identity of online support services and be cautious when interacting with chatbots that seem too good (or helpful) to be true. Remember, security is everyone’s responsibility – stay informed, stay vigilant, and never underestimate the power of a well-crafted phishing lure.


Source: The Hacker News — 2026-09-30