Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Attackers Abuse ChatGPT Custom GPTs to Deploy a Full‑Featured Remote Access Trojan

Threat actors leveraged legitimate ChatGPT Custom GPT pages to deliver a multi‑stage PowerShell‑based RAT, compromising at least 40 victims. The abuse highlights the need for continuous third‑party risk monitoring and audit‑ready evidence of AI service controls.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Attackers Leverage ChatGPT Custom GPTs to Distribute a Multi‑Stage Remote Access Trojan

What Happened – Threat actors created malicious “Custom GPT” pages on the legitimate chatgpt.com domain. When a user clicks a sponsored search result, the GPT redirects to a fake Cloudflare CAPTCHA on a Google Sites page, then delivers a ClickFix PowerShell one‑liner that downloads a signed MSI‑based RAT. Huntress observed at least 40 incidents, including two confirmed infections, and reported the abuse to OpenAI, which removed the offending GPTs only to see replacements appear within days.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a trusted third‑party AI service can become an un‑vetted attack surface, underscoring the need for continuous vendor‑risk monitoring and evidence of due‑diligence.
  • Highlights the importance of logging and correlating web‑proxy, DNS, and endpoint telemetry to detect the multi‑stage delivery chain in real time.
  • Shows that control‑assurance programs must include verification of AI‑generated content and associated URLs before they are allowed in the corporate workflow.

Who Is Affected – Enterprises across all sectors that permit employees to use ChatGPT (or similar generative AI tools) for productivity, especially technology‑SaaS firms, professional services, and any organization with open web access.

Recommended Actions

  • Enforce web‑filtering rules that block unknown “chatgpt.com/custom‑gpt” URLs and Google Sites pages used for ClickFix lures.
  • Require explicit approval and continuous monitoring of any third‑party AI services before they are added to the corporate allow‑list.
  • Capture and retain PowerShell command‑line logs, MSI installation events, and scheduled‑task creation alerts for forensic correlation.
  • Conduct a rapid review of signed binaries used in the infection chain (Canon, Stardock) against your software‑allow‑list.
  • Update security awareness training to include AI‑driven phishing scenarios.

Technical Notes – The campaign uses a sponsored search ad to drive victims to a custom GPT titled “Plus 5.6.” The GPT replies with a “limited availability” message and a link to a backup domain hosted on Google Sites. The backup page presents a fake Cloudflare CAPTCHA, then instructs the user to copy a PowerShell command (using a decimal IP format) into the Windows Run dialog. The command downloads a 27 KB script composed of negative numbers, decodes it in memory, and installs a signed MSI (ISOSimple.msi) that masquerades as a printer‑configuration tool. Persistence is achieved via a Run‑key entry and a scheduled task; the payload loads additional code through DLL sideloading with legitimate signed executables. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/200079/ai/attackers-abuse-chatgpt-custom-gpts-to-deploy-a-full-featured-rat.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →