Attackers Weaponise ChatGPT Custom GPTs to Deliver RAT via Eight-Stage ClickFix Chain
· Technology · IT Security Guru, Android Authority
Attackers are weaponising ChatGPT Custom GPTs to distribute Remote Access Trojans through an intricate eight-stage ClickFix infection chain. The malicious campaign exploits AI tools to trick users into executing fraudulent software updates that compromise system security. Researchers discovered that the attack vector relies on social engineering tactics embedded within custom conversational workflows. The exact identity of the threat actors and the full scale of infections remain under investigation. Cybersecurity analysts recommend verifying all external script executions and avoiding unverified links generated through AI assistants.
Why it matters
This campaign demonstrates how attackers are successfully repurposing legitimate generative AI tools into delivery systems for advanced malware. Organisations and everyday users relying on custom conversational agents face heightened security risks as threat actors pioneer novel social engineering vectors.
Read the original report — IT Security Guru
Join us on Telegram
Breaking news the moment it lands. At 10,000 members we ship the Android app.