Skip to content
Cybercriminals Exploit ChatGPT Custom GPTs for ClickFix RAT Attacks

Cybercriminals Exploit ChatGPT Custom GPTs for ClickFix RAT Attacks

First seen 29 Sep 2026, 15:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 16:22 UTC
  • •Attackers are using ChatGPT Custom GPTs to distribute malware via ClickFix techniques.
  • •At least 40 users have been confirmed infected, with two incidents linked to Custom GPTs.
  • •OpenAI has removed the malicious Custom GPTs, but new instances continue to appear.

A new ClickFix campaign has been discovered that exploits ChatGPT Custom GPTs to impersonate legitimate products, luring users into executing malicious code. Cybersecurity firm Huntress reported that at least 40 users have been infected, with two confirmed incidents linked to Custom GPT instances. The attackers created Custom GPTs that directed victims to a Google Sites link, leading to a malicious page that instructed users to run PowerShell commands to download a malicious MSI file. This file then deployed a remote access trojan (RAT) by sideloading malicious DLLs using legitimate Canon and Stardock executables. OpenAI took down the first Custom GPT on September 25, but a second one was discovered shortly after. The campaign highlights the ongoing abuse of AI platforms for social engineering attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-01-13
CVE-2025-25249 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-25
First malicious Custom GPT taken down
OpenAI removed the first Custom GPT involved in the ClickFix campaign after Huntress reported it.
Securityweek
2026-09-27
Second malicious Custom GPT discovered
Huntress researchers found a second Custom GPT still online, continuing the ClickFix attack method.
Securityweek
2026-09-28
CVE-2026-86950 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-29
Campaign reported by Huntress
Huntress reported the ClickFix campaign, detailing the infection method and impact on users.
Huntress

More articles in this cluster (4)

Following this threat?

Track ClickFix, Cloudflare and CVE-2025-25249 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed