Threat Actors Weaponize ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
What Happened — Threat actors are exploiting the “Custom GPT” feature in ChatGPT to pose as legitimate product offerings. The malicious GPTs redirect victims to ClickFix‑styled lure pages that host remote‑access trojans (RATs). Huntress first observed the campaign in late September 2026.
Why It Matters for Trust & Control Assurance
- This scenario tests an organization’s AI governance controls – the ability to monitor, approve, and audit the use of generative‑AI tools that could be weaponized.
- Continuous control‑assurance programs need evidence that AI‑related policies are enforced and that user‑generated content is inspected for malicious intent.
- The Security Awareness capability helps embed detection of AI‑driven social‑engineering into training and phishing simulations, providing a defensible audit trail of user readiness.
Who Is Affected – SaaS AI providers, enterprises that integrate ChatGPT via API, and any organization whose staff interact with custom GPTs (technology, finance, healthcare, etc.).
Recommended Actions
- Update security‑awareness curricula to cover AI‑generated phishing and malicious GPT use.
- Enforce a policy requiring vetting and logging of all custom GPT deployments.
- Deploy URL‑reputation and sandboxing solutions to inspect links originating from AI‑generated content.
- Capture evidence of AI‑tool usage for audit readiness and continuous monitoring.
Technical Notes – The attackers embed malicious URLs in the output of custom GPTs, leveraging ClickFix‑style landing pages that automatically trigger RAT downloads. No specific CVE is involved; the vector is social engineering combined with AI content generation. Source: https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html