Threat actors are abusing ChatGPT Custom GPTs to impersonate as legitimate product offerings to lure unsuspecting victims into malicious sites, which are using ClickFix lures to deliver malware.
Huntress, who witnessed the activity in late September 2026, reported it is another abuse of yet another feature in trusted artificial intelligence (AI) platforms. Earlier campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs).
Custom GPTs are a personalized version of ChatGPT that, as the name suggests, allow users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. They are hosted on the legitimate ChatGPT website with the Custom GPT name at the top.
In the incidents we saw, victims were interacting with an attacker-created Custom GPT that was programmed to reply to their prompts with a message containing a Google Sites link,” Huntress said. This link led them to a ClickFix-style attack, which resulted in the download and execution of a malicious MSI installer read more about Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
