Threat Actors Weaponize Custom ChatGPT Models to Distribute Remote Access Trojans

Attackers created malicious custom ChatGPT variants distributed through sponsored Google search results to trick users into executing PowerShell commands that install remote access trojans. The campaign leveraged OpenAI's custom GPT feature to host malicious instructions on the legitimate ChatGPT domain, increasing credibility and victim compliance. The deployed malware provided remote desktop access, surveillance capabilities, and system reconnaissance while establishing persistence through Windows Registry and scheduled tasks.
This campaign represents an evolution in social engineering tactics, where attackers exploited a legitimate platform feature rather than creating entirely fake services. By hosting malicious instructions on OpenAI's actual domain, the threat actors significantly increased user trust and compliance rates compared to traditional phishing approaches. The infection payload itself demonstrates sophisticated obfuscation techniques, including a custom-built encrypted file system designed to evade detection tools that typically scan for conventional file structures.
The attackers' ability to rapidly adapt their methods—shifting from Canon-signed to Stardock-signed applications and modifying delivery mechanisms within days—underscores how quickly threat actors can iterate when their infrastructure is identified and dismantled. This agility suggests the campaign operators possessed sufficient resources and technical knowledge to maintain operational effectiveness despite disruptions.
This attack vector could significantly impact both individual users and organizations relying on AI assistants for work. As AI platforms become more integrated into daily workflows, users may struggle to distinguish between legitimate and malicious AI-generated content, particularly when hosted on trusted domains. Organizations may need to implement stricter controls on PowerShell execution and establish clearer employee protocols for unusual system requests. The incident also raises questions about platform responsibility in preventing feature abuse, potentially influencing how AI companies design and monitor custom tool ecosystems going forward.