# Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

> **Open Intelligence Dossier** · First detected: 2026-10-01 15:20 UTC · Category: Technology

## Executive Summary
Attackers are leveraging official ChatGPT Custom GPTs and fake Google ads to deliver Remote Access Trojans (RATs) via ClickFix lures.

## Intelligence Brief
Threat actors are currently exploiting the Custom GPT feature on ChatGPT&amp;#039;s official website to facilitate malware infections. According to reports from The Hacker News and Dark Reading, these attackers are utilizing malicious Custom GPTs to deliver Remote Access Trojans, commonly known as RATs, through a technique described as ClickFix lures. This method leverages legitimate ChatGPT pages as entry points to deceive users into installing harmful software on their systems. The operation involves hosting fake ChatGPT models directly on the official platform, turning a trusted environment into a delivery mechanism for malicious payloads. Coverage from multiple outlets emphasizes the multi-pronged nature of this campaign. Cybernews reports that over 850 fake ChatGPT advertisements have been identified on Google, specifically targeting Windows users to trick them into installing malware.


GIGAZINE highlights that the exploitation of Custom GPTs allows attackers to use legitimate pages, which likely increases the perceived trust of the victim. TechRadar further confirms that hackers have successfully hosted these fake models on the official website, effectively weaponizing the platform&amp;#039;s own customization tools to bypass traditional user skepticism regarding third-party links. This trend is significant because it represents a shift in how malware is delivered, moving from external phishing sites to the interior of trusted, high-traffic platforms. By using the official ChatGPT domain, attackers can bypass certain security perceptions that usually alert users to fraudulent activity. The use of ClickFix lures suggests a social engineering approach where users are prompted to fix a perceived technical error, leading them to execute the RAT. This allows the attackers to gain remote control over the infected Windows machines, as noted in the reporting by Cybernews regarding the specific targeting of that operating system.


Future developments to monitor include whether OpenAI implements new verification measures for Custom GPTs to prevent the hosting of such fake models. Based on the coverage from The Hacker News and Dark Reading, the primary point of concern remains the delivery of RATs via these lures. Additionally, the persistence of the 850+ fake Google ads reported by Cybernews indicates an ongoing effort to funnel Windows users toward these malicious infections. Observers should watch for updates on how these official pages are being flagged or removed to stop the distribution of the Remote Access Trojans.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| Android Authority | A real ChatGPT page is being used to trick people into installing malware | [Source Link](https://news.google.com/rss/articles/CBMifkFVX3lxTE16UXpUUmtpUnQwVmN6aEhMZEFKTHlUTS1UNkxVelRMR1BNMlZLeDJuMUd5Q0wwak1YLXhoNzNSbkhKM3JwbXpXNGxJcFlTSVQwYk85ZFE3clVzNGNFbmpFMWt4eFlUX2I4MXNxVGNQT1dyZ2pMdkV2dHpaM0NaQQ?oc=5) |
| Cybernews | 850+ fake ChatGPT ads on Google trick Windows users into installing malware | [Source Link](https://news.google.com/rss/articles/CBMijwFBVV95cUxPNWlCZGxac2RDV1pGWDM1MUY5X1M3TWtWdEtIZ19LY0dvQzM2clp6N21ZelJFZzJQaWFfdUF1eDhWSExqeWltTWpfRzZ0UTlJQkNtX0JjYlB6eFBWYzQ2U1RlNzMxSnVvQzE4Ung3bWNPZkRxN2QwbDRuZHFHdjB0bXl5eUI0YWZIQXBRbGdjdw?oc=5) |
| GIGAZINE | Attacks exploiting ChatGPT's 'Custom GPT' to lead to malware infections, using legitimate ChatGPT pages as entry points. | [Source Link](https://news.google.com/rss/articles/CBMidEFVX3lxTE9VWmFHN0U5a2FBV3lueHkxN2NjVFpIUmlXQWpWMkptbjhISFpuX1JiNkJpVmcwMFpaVkU4ZjlYUnRtOThQU24tUENldV9xdU9GOGRXUGZXdWtQZnotNkxRZkVxWEpLRFB3dXBzcE1XOFotNnY3?oc=5) |
| TechRadar | Hackers host fake ChatGPT model on its official website — but really it's just malware | [Source Link](https://news.google.com/rss/articles/CBMivwFBVV95cUxPcHp4X1FhZmIyR0ZLUEFXRkJydm01QkZhb0RVM1dVX1FtRzFKZjdTcTZ1NFk1WjF2LUJOaEo4TTU5NzJMLTIyQlZ5OVE2LWd1emFQN01mNmpTS2d0Y2k1QnAyV1ptaVVUS2lNb1ZNUzF4bTNrT3B0YlpxQ2N6VEhWdTJIbnoxZlVib0JMdkR6NmVXVmVuTWtVZ19qX3lDSVdRSjN5dkVmOWpqUlFHWEdKNzZ6Qks4RGw3YlhaRlpQYw?oc=5) |
| Dark Reading | Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure | [Source Link](https://news.google.com/rss/articles/CBMipAFBVV95cUxPSzhhSEVtR3QwU1BPQ0RNUDZaS3RaVWVUT3lPRW9sbjdGZ0w4MGZlOGp3WUtIYjQ0LUluZmIza3FqenFiMWU4TjdtY0RiZXl6S3V5Q3duVFFwbVh4RnNiNFE1c2M0TVMxaEN4SGswcFlzLWtHTkRGQU1VMndwODg4Rk5ubnhjWnRrZDFBTGlpTjFSU1VvcTdSN2R5R1FWX2JxVDd3VQ?oc=5) |
| The Hacker News | Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures | [Source Link](https://news.google.com/rss/articles/CBMigwFBVV95cUxQZWRmTmFtNjRVZWlaSTdwVkZidTlqTU9HMm4yOVBhTjBueklsbGxiRmhSUTFMYW9vQnZmQ2ltaTNaUENCMjd4M2dGOUVFejNWMjlBTm5sUTRPWUQ1TjdTZGRSTmxRQjFMcU5UTGt4QmV6VENPdDlZRVhrOFRDc0Q3YkN0NA?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-10-01/attackers-abuse-chatgpt-custom-gpts-to-deliver-rat-via-clickfix-lures*
