Malicious Custom GPTs Used as Lures to Deliver Remote‑Access Trojans via ChatGPT
What Happened — Threat actors are publishing custom GPTs on OpenAI’s platform and on Google‑hosted domains. The bots masquerade as helpful assistants but embed links that download Remote‑Access Trojans (RATs) onto the victim’s machine when users click. The campaign mirrors earlier “ClickFix”‑style operations that weaponize trusted services to trick users.
Why It Matters for Trust & Control Assurance
- Demonstrates how a legitimate third‑party AI service can become an indirect attack vector, stressing the need for continuous monitoring of vendor‑provided content.
- Highlights the importance of security‑awareness programs that teach users to verify download sources, even when they appear inside trusted AI chat interfaces.
- Aligns with control objectives around vendor oversight and identity‑based access controls, which are essential for building a defensible audit trail of user interactions with external services.
Who Is Affected – SaaS providers, enterprise users of generative AI, and any organization that permits employees to interact with public AI models (Technology / SaaS, Cloud Infra, Professional Services).
Recommended Actions
- Refresh security‑awareness training to cover AI‑driven social‑engineering tactics and the risks of downloading files from chat outputs.
- Deploy web‑proxy or DLP rules that flag executable downloads originating from AI chat sessions.
- Incorporate vendor‑risk checks that assess the security posture of AI platform providers and monitor for abuse of their domains.
Technical Notes – The attackers host malicious payloads on compromised or rented domains that share the same DNS suffixes as OpenAI and Google services. The delivery chain relies on user‑initiated clicks from chat responses, not on a software vulnerability. Source: Dark Reading