News report
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
What Happened
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
Why This Matters
This is source reporting of a security event, not a confirmed product vulnerability or patchable CVE. Use it as situational awareness if named organizations, cloud tenants, or identity systems overlap with yours.
Recommended Action
Read the source report. Confirm whether any named organizations, identity tenants, or cloud environments you operate are implicated. Do not treat this as a vendor advisory unless a CVE or official bulletin is attached.
Exposure
Exposure unknown
Sep 30, 2026 20:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Sep 30, 2026 20:30BugSkan first recorded this incident.
-
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Sep 30, 2026 20:30thehackernews.com · News
Sources
thehackernews.com · Sep 30, 2026 20:30
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.