Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
The Hacker News reports that attackers are abusing ChatGPT custom GPTs to deliver a remote access trojan (RAT) via ClickFix lures. The source describes the custom GPT feature as the abused component in the delivery chain, with ClickFix-style lures leading to the RAT payload. The report does not identify the specific RAT family, the number of victims, or the geographic scope of the activity. The source does not state how the malicious custom GPTs were distributed, whether they were published in a public GPT store, or how long they remained available. It also does not describe any response from OpenAI, any takedown of the GPTs, or any remediation guidance. No indicators of compromise, command-and-control details, or file hashes are provided in the excerpt. Because the source text is limited to the headline and framing, the digest is restricted to what is explicitly stated: custom GPTs were abused, ClickFix lures were used, and the payload was a RAT.
The report indicates that custom GPTs can be used as a delivery vector for malware lures, which is relevant to developers who build or distribute GPT-based tools.