Malicious Custom GPT on ChatGPT Tricks Users into Downloading RAT Malware
Malicious Custom GPT instances hosted on chatgpt.com have been used to trick users into deploying a remote access trojan.
Campaign Overview
Security researchers have identified a campaign targeting users through compromised Custom GPT configurations. The Huntress Security Operations Center reported handling over 40 incidents linked to a specific Google Sites domain associated with this attack. Two of these cases involved exploitation of a Custom GPT environment, according to the firm’s analysis.
Attack Mechanism
The malicious activity emerged in late September, with attackers embedding links to compromised Custom GPT pages within the legitimate chatgpt.com platform. These pages, created using ChatGPT’s customization features, displayed error messages indicating service unavailability and redirected users to a Google Sites-hosted backup domain. The fake interface mimicked a CloudFlare CAPTCHA verification process, prompting victims to execute a ClickFix-style attack. Users who followed the instructions were directed to copy and paste a command into their terminal, initiating a multi-stage infection chain. This process leveraged digitally signed executables from Canon and later Stardock to deploy a fully functional remote access trojan.
Response and Evolution
After the initial malicious Custom GPT was removed by OpenAI, threat actors quickly deployed a successor variant. While the second iteration no longer uses the ClickFix lure, researchers note that attackers are developing an updated installer. The campaign’s ephemeral nature allows it to evade detection, with malicious content typically remaining active for hours or days. Despite its short lifespan, the attack vector has proven effective in compromising systems.
Security Recommendations
End users are advised to recognize that no legitimate service will request command execution through terminal interfaces, run dialogs, or command prompts. Organizations must implement layered security strategies, including user training to identify social engineering tactics, restrictions on privileged system commands, and enhanced monitoring capabilities to detect suspicious activity. The attack highlights the evolving tactics of cybercriminals leveraging trusted platforms for malware distribution.
Security teams are urged to remain vigilant against emerging threats exploiting AI-driven tools and cloud services.
