Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

Threat actors are abusing legitimate OpenAI and Google infrastructure, including malicious Custom GPTs, to lure users into a ClickFix-style infection chain that installs remote access Trojans (RATs) and additional malware. For CIOs and technology leaders, this is a reminder that trusted AI platforms can be weaponized as delivery channels, increasing the risk of credential theft, endpoint compromise, and broader enterprise intrusion even when employees believe they are interacting with sanctioned services. IT organizations should assume attackers will exploit user trust in reputable SaaS and AI tools, making layered endpoint controls, web filtering, and rapid detection/containment essential.

Alexander CulafiDark Reading2 min read
Read full article
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure

Read the full story at Dark Reading →