cd /news/ai-safety/attackers-weaponise-chatgpt-custom-g… · home › topics › ai-safety › article
[ARTICLE · art-141644] src=itsecurityguru.org ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain

Threat actors are abusing ChatGPT's Custom GPT feature to deliver a remote access trojan (RAT) through an eight-stage ClickFix chain, according to new research from Huntress. The attackers created a Custom GPT titled "Plus 5.6" that impersonates a genuine ChatGPT model, and because Custom GPTs are hosted on chatgpt.com, the malicious page inherits the platform's trusted domain. The campaign funnels victims from the trusted ChatGPT domain into the multi-stage ClickFix infection that ends with a full-featured RAT.

by read1 min views1 publishedSep 29, 2026

Threat actors are abusing ChatGPT’s Custom GPT feature to funnel victims into a ClickFix attack that ends with a full-featured remote access trojan (RAT), according to new research from Huntress. The attackers created a Custom GPT titled “Plus 5.6”, designed to pass as a genuine ChatGPT model. Because Custom GPTs are hosted on chatgpt.com, the […]

The post Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain appeared first on IT Security Guru.

── more in #ai-safety 4 stories · sorted by recency
── more on @chatgpt 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/attackers-weaponise-…] indexed:0 read:1min 2026-09-29 · —