Cybercriminals Exploit ChatGPT Custom GPTs for RAT Delivery via ClickFix Lures
Threat actors are exploiting ChatGPT Custom GPTs to distribute a remote access trojan (RAT) through ClickFix lures, using social engineering and DLL sideloading techniques to bypass security measures. The malware employs advanced evasion methods, including AMSI bypass and anti-VM checks, while leveraging legitimate signed binaries for persistence and data exfiltration.
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.
Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
*** END OF TRANSMISSION ***