Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
What happened
Threat actors are exploiting ChatGPT Custom GPTs as trojan horses by disguising them as trusted product offerings. These fake GPTs steer users to malicious websites where ClickFix lures are employed to deliver remote access trojans (RATs). Huntress observed this new attack vector in late September 2026, marking a fresh tactic that weaponizes features of widely trusted AI platforms to push malware.
The risk
This abuse lowers the trust boundary that operators place on AI-driven extensions and custom agents. The attack carefully masks itself within a legitimate AI environment, which makes it easier to fool targets who assume AI products are inherently safe. The use of ClickFix lures adds to the sophistication by tricking users into installing malware disguised as helpful fixes, increasing the chance of compromise and persistence through RATs.
Why it matters
Businesses, developers, and IT operators face new pressure to tighten vetting procedures for any Custom GPTs or AI extensions before deployment. The incident exposes how AI platform features, meant to empower users, can amplify risk when abused. In environments where AI bots integrate with workflows or customer interactions, this vector raises the stakes for endpoint security and user training. Attackers leveraging AI brand trust force defenders to reconsider how they validate AI assets and respond to suspicious behaviors.
Who should pay attention
Security teams monitoring AI integrations and organizations embedding Custom GPTs must prioritize detecting abnormal redirect patterns and user interactions following AI-driven recommendations. Developers creating Custom GPTs should implement stringent access controls to prevent unauthorized modifications that enable these abuses. Investors and buyers advocating for secure AI adoption should press vendors to strengthen delivery safeguards.
What to watch next
Watch for similar abuse across other AI platforms offering extensibility and customization features. Expect defenders to update their threat detection tools to flag malicious GPT-related activity and ClickFix lure techniques. The evolving threat will likely push platforms to introduce stronger validation, signing, or sandboxing mechanisms for Custom GPTs to limit their misuse.
AI Quick Briefs Editorial Desk