Threat actors are weaponizing OpenAI's Custom GPTs feature to launch Remote Access Trojan (RAT) attacks against unsuspecting users. Security researchers at Huntress detected the campaign in late September 2026, identifying a new vector that exploits user trust in legitimate AI platforms.

The attack chain begins with malicious Custom GPTs designed to impersonate established software products. These fake GPTs direct victims to malicious websites that host ClickFix lures. ClickFix is a social engineering technique that displays fake browser alerts claiming the system is compromised, prompting users to download and execute files. In this case, the downloaded files deliver RAT malware that grants attackers remote access and control over infected machines.

The exploitation of Custom GPTs represents a shift in how attackers abuse artificial intelligence infrastructure. OpenAI introduced Custom GPTs in late 2023 to allow users to create specialized, pre-configured versions of ChatGPT for specific tasks. These customized models inherit the credibility associated with ChatGPT itself. Attackers capitalize on this trust by creating GPTs that pose as tech support tools, security scanners, or software installers. Users who interact with these malicious GPTs receive socially engineered prompts directing them to visit attacker-controlled domains.

This campaign adds to a growing list of AI platform abuses. Previous threat actors have weaponized other OpenAI features, including shared links and file-sharing capabilities. Each new vector exploits the fundamental trust users place in mainstream AI platforms. Most users assume that GPTs available through ChatGPT's interface undergo some form of vetting, making them less likely to question suspicious prompts or downloads.

The RAT payloads used in these campaigns grant attackers multiple capabilities. RATs enable keystroke logging, screen capture, file theft, credential harvesting, and lateral movement within networks. Organizations with employees using personal ChatGPT accounts face heightened risk. A single compromised machine can serve as an entry point for broader network compromise, especially in environments with weak endpoint detection or segmentation.

Huntress recommends organizations implement email and web filtering rules to block known malicious domains associated with the campaign. Endpoint Detection and Response (EDR) tools should flag RAT execution patterns and process injection attempts. User awareness training remains critical. Employees should understand that downloading files from any web source, regardless of the source platform, carries risk if the content wasn't explicitly requested through verified business channels.

For individual users, exercising caution with Custom GPTs is essential. Verify the publisher information of any GPT before use. Cross-check software download links against official vendor websites rather than links provided by third-party tools. Enable browser warnings for suspicious sites. Keep security software updated and run periodic scans for RAT-associated signatures.

OpenAI has not publicly announced specific mitigations for this campaign variant. However, the company does allow Custom GPT creators to set usage policies and implement domain restrictions. Tighter vetting of Custom GPT creators and clearer labeling of third-party or less-reviewed GPTs would reduce user exposure to malicious variants.

This campaign demonstrates that attackers continuously adapt to new technological surfaces. As AI platforms become more integrated into daily workflows, their misuse as delivery mechanisms will accelerate. Organizations should treat Custom GPTs the same as any untrusted third-party software source.