Attackers Weaponize OpenAI's GPT Platform to Distribute Remote Access Trojans

Threat actors have created malicious custom GPTs that leverage ChatGPT's trusted interface to deliver remote access trojans to victims through a social engineering technique similar to prior ClickFix campaigns. The attackers impersonate legitimate domains belonging to OpenAI and Google to increase credibility and trick users into downloading malware. This approach exploits the growing popularity of AI tools and users' trust in established technology platforms.
Cybercriminals have begun exploiting OpenAI's custom GPT functionality as a delivery mechanism for remote access trojans, a form of malware that grants attackers control over infected systems. The attack method mirrors earlier ClickFix campaigns, which used social engineering to persuade users to download harmful software. By creating fraudulent GPT applications and spoofing the appearance of recognized tech companies, threat actors capitalize on the credibility associated with established platforms.
This campaign highlights an emerging challenge in AI security: as customizable AI tools proliferate and gain mainstream adoption, their trusted interfaces become attractive vectors for malicious actors. The approach exploits a critical vulnerability in user behavior—the assumption that interactions with well-known platforms and their interfaces are inherently safe, even when warning signs may be present.
This development could significantly impact individual users and organizations relying on AI tools for legitimate purposes. Users may become more cautious about interacting with custom GPTs or AI services generally, potentially hindering broader adoption of beneficial AI applications. Businesses may face increased pressure to implement stricter security protocols and user education programs. The incident underscores how rapidly emerging technologies can be weaponized and suggests that AI platform providers may need to strengthen verification systems and content moderation to prevent similar exploitations.