Threat actors are abusing ChatGPT Custom GPTs to make malicious destinations look like legitimate AI product offerings, according to reporting based on Huntress research. The campaign directs victims to a Google Sites link and then to a ClickFix-style lure that attempts to persuade them to run a malicious installer.

The reported infection chain uses a familiar social-engineering pattern: a trusted platform supplies the initial credibility, a fake availability or verification message creates urgency, and a user is pushed into executing code. The reporting says the subsequent chain uses DLL sideloading and ultimately deploys a remote-access trojan. Huntress observed the activity in late September 2026.

For defenders, user-facing warnings about copying commands from web pages remain relevant even when the initial lure is an AI service. Block or investigate suspicious Google Sites destinations, monitor for unusual MSI installation and signed-binary sideloading behavior, and alert on suspicious PowerShell execution. Security teams should also review web-filtering, endpoint detection, and browser-isolation controls around untrusted links. Treat unexpected service-upgrade or CAPTCHA instructions that require code execution as a high-confidence social-engineering signal.

Source: The Hacker News: Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures; Huntress research.

By Allan