Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
BLUF
AI chatbots are being weaponized as new delivery mechanisms for remote access malware via social engineering.
NEWS
A new ClickFix-style campaign leverages malicious Custom GPTs to distribute RATs by directing victims to execute harmful commands. Attackers spoof legitimate OpenAI and Google domains to increase credibility and evade detection during the infection chain.
Why I Care
This evolution in AI-driven phishing lowers the barrier for sophisticated attacks, putting enterprise users and consumers at risk of full system compromise. Organizations relying on AI tools may face increased insider threats and data exfiltration if employees interact with unverified GPTs.
Next Steps
Security teams should audit approved Custom GPTs and implement strict allowlisting for AI tool usage immediately. Users must be trained to verify command execution requests and avoid running scripts from chatbot interactions without IT approval.
Source: Dark Reading ·