Last seen September 30, 2026

News report

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

Category
News
Lifecycle Status

NEW

What Happened

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

Why This Matters

This is source reporting of a security event, not a confirmed product vulnerability or patchable CVE. Use it as situational awareness if named organizations, cloud tenants, or identity systems overlap with yours.

Recommended Action

Read the source report. Confirm whether any named organizations, identity tenants, or cloud environments you operate are implicated. Do not treat this as a vendor advisory unless a CVE or official bulletin is attached.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 30, 2026 20:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

OpenAIChatGPTChatGPT Custom GPTsClickFix LuresCustom GPTsHuntress

Timeline

  • Incident first seen
    Sep 30, 2026 20:30

    BugSkan first recorded this incident.

  • Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
    Sep 30, 2026 20:30

    thehackernews.com · News

Sources

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

thehackernews.com · Sep 30, 2026 20:30

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence