Malicious Ads Promote Custom ChatGPTs That Deploy ClickFix RATs
Security researchers have identified a new wave of malicious campaigns that exploit custom versions of OpenAI's ChatGPT, advertised through paid Google search results. These tailored chatbots act as gateways to websites that launch ClickFix attacks, a technique that silently installs remote access trojan (RAT) malware on unsuspecting visitors' computers.
The campaigns appear to target users searching for AI chat tools, with the sponsored links promising enhanced or specialized chatbot experiences. Once a user clicks the ad and interacts with the custom ChatGPT interface, the site triggers a hidden ClickFix exploit that leverages browser vulnerabilities to download and execute malicious code without the user's knowledge.
ClickFix attacks have been observed in the wild for several years, typically involving the injection of malicious scripts into compromised web pages. In this instance, the malicious actors have combined the technique with the popularity of generative AI, using the allure of a customized chatbot to increase click-through rates. The resulting RATs grant attackers remote control over infected machines, enabling data theft, credential harvesting, and the deployment of additional payloads.
OpenAI has not been directly implicated in the malicious activity, and the company’s official ChatGPT platform remains separate from the custom implementations promoted in the ads. Nonetheless, the incidents underscore the broader security challenges posed by the rapid proliferation of AI-driven services, especially when third parties can repurpose the underlying model for their own ends. Users are advised to verify that any ChatGPT service they access originates from a reputable source, such as the official OpenAI website or recognized partners.
Cybersecurity firms are urging search engine operators to tighten controls over sponsored listings that reference AI technologies, and to improve detection of deceptive ad content. Meanwhile, security researchers continue to monitor the threat landscape for similar schemes that blend emerging tech trends with established exploitation methods. As the public’s reliance on AI assistants grows, vigilance against such hybrid attacks will be essential to protect both individual users and organizational networks.
Comments (0)
Be the first to comment.
Join the discussion