ThreatCluster

Malicious Use of ChatGPT Links to Distribute NetSupport RAT

First seen 1 Sep 2026, 21:30 UTC GbhackersCybersecuritynews 62

Article Content

Browse articles
ThreatCluster

Threat actors are exploiting legitimate ChatGPT shared links to deploy the NetSupport remote-access tool (RAT) through social engineering tactics. Victims are misled by a fabricated message claiming high traffic on the ChatGPT platform, prompting them to follow malicious instructions. The attack primarily targets Windows users, steering them into a ClickFix-style infection chain. The specific shared link used in the attack is chatgpt.com/s/t_6a80bc61c434819190c3eae5932307e8. This campaign highlights the increasing use of trusted platforms for malware distribution. Current reports indicate ongoing exploitation of this method, affecting a wide range of users. The full scope of the impact is still being assessed as the campaign unfolds.

Key Points: • Hackers are abusing ChatGPT shared links to deliver malware. • Victims are tricked into following malicious instructions under false pretenses. • The NetSupport RAT is the primary tool used in this campaign.

Timeline

2026-09-01
Malicious campaign identified
Threat actors began exploiting ChatGPT shared links to distribute NetSupport RAT via social engineering tactics targeting Windows users.
Gbhackers
2026-09-01
Attack method detailed
Victims are misled by a fabricated message claiming high traffic, leading them to follow malicious instructions.
Cybersecuritynews