Threat actors have weaponized custom GPTs, the application layer built on OpenAI's ChatGPT platform, to distribute remote access trojans (RATs) to unsuspecting users. The attack mimics ClickFix campaigns by spoofing legitimate domains from OpenAI and Google, creating a veneer of authenticity that exploits user trust.
Custom GPTs, which allow developers to build specialized AI applications without coding, have become a delivery vector for malware. Attackers create fake GPT applications designed to appear official or helpful. When users interact with these malicious custom GPTs, they receive instructions that ultimately lead to RAT installation. The campaign leverages the reputation of legitimate platforms to bypass user skepticism.
The ClickFix pattern referenced in this attack is a well-established social engineering tactic. ClickFix campaigns typically trick users into downloading malware by presenting fake system alerts or error messages. By adapting this approach to custom GPTs, threat actors exploit the growing adoption of AI tools and the perception that anything hosted on OpenAI's platform carries implicit trust.
Domain spoofing plays a central role in the deception. Threat actors register domains that closely resemble OpenAI and Google properties or abuse subdomain capabilities to create convincing URLs. Users clicking links from seemingly official sources remain unaware they are interacting with attacker-controlled infrastructure. The custom GPT interface itself masks the actual source of the malicious instructions.
The RAT delivered through these campaigns provides attackers with remote control capabilities. Once installed, RATs allow threat actors to access infected systems, steal credentials, exfiltrate sensitive data, monitor user activity, and pivot to other networks. Organizations and individuals running compromised systems face credential theft, data breaches, and lateral movement risks.
The sophistication of this attack vector reflects how threat actors adapt to emerging technologies. Custom GPTs represent a relatively new surface area for abuse. Unlike traditional phishing emails or malware distribution networks that users have learned to recognize, AI-powered applications feel novel and less suspect. Users trust the ChatGPT brand, and custom GPTs leverage that trust.
Organizations should educate users about verifying URLs before interacting with custom applications. Even if a GPT appears to be hosted on OpenAI's platform, users should confirm the application's legitimacy through official channels. Administrators should monitor for suspicious custom GPT interactions and block access to known malicious instances.
OpenAI and Google bear responsibility for detecting and removing malicious custom GPTs faster. Platform moderation must keep pace with threat actor innovation. Both companies should implement stronger verification for custom GPT creators and provide clearer warnings when applications come from unverified sources.
Endpoint detection and response solutions should flag unusual behavior following custom GPT interactions, particularly downloads or execution of unknown binaries. Network monitoring can identify command-and-control traffic associated with RATs once installed.
This campaign demonstrates that threat actors will exploit any platform gaining user adoption. As AI tools become mainstream, security teams must treat them as potential attack surfaces rather than inherently trustworthy services. The intersection of legitimate platforms and malicious abuse creates persistent risk for users who lower their guard around established brands.
