Malicious Custom GPTs Exploit Trusted Domains to Distribute Remote‑Access Trojans
Security researchers have uncovered a new wave of attacks that weaponize custom versions of ChatGPT to serve as bait for remote‑access trojan (RAT) distribution. By publishing these tailored bots on legitimate OpenAI and Google domains, threat actors hope to convince unsuspecting users that the interactions are safe, then deliver malicious payloads once a link is clicked.
The technique mirrors earlier "ClickFix"‑style campaigns, where attackers masquerade as technical support or software update services to trick victims into installing malware. In this iteration, the lure is a conversational AI that appears to offer assistance, but the dialogue steers users toward downloading an executable disguised as a helpful tool.
OpenAI’s platform allows developers to create custom GPTs that can be hosted under the company’s own subdomains, while Google’s cloud services provide similar capabilities for hosting AI‑driven applications. Researchers say the malicious actors are exploiting the inherent trust users place in these high‑profile domains, making the phishing component more convincing than typical email‑based scams.
Analysis of the malicious bots shows they embed links to compressed archives that, once extracted, drop RATs capable of full system control. The trojans observed in the campaign include well‑known families that enable keystroke logging, screen capture, and lateral movement across corporate networks. Because the initial contact occurs through a seemingly benign chat interface, traditional email filters and web‑gateway defenses may not flag the traffic.
OpenAI has responded by tightening verification procedures for custom GPT publishing and is working with security partners to identify and remove abusive instances. Google’s cloud security team is also reviewing the misuse of its hosting services and has issued guidance for developers to monitor for suspicious outbound requests from AI‑driven applications.
Experts advise users to treat any unsolicited request for software downloads—especially those delivered through chat interfaces—as potentially unsafe. Verifying the source, checking digital signatures, and employing endpoint protection that can detect RAT behavior remain critical defenses. As AI tools become more accessible, security professionals warn that attackers will continue to repurpose them for deception, underscoring the need for vigilant monitoring of both AI platforms and the domains that host them.
Comments (0)
Be the first to comment.
Join the discussion