Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Executive Summary

Custom ChatGPT variants promoted via sponsored Google results lure users to malicious sites that use ClickFix attacks to deliver remote access trojans. Attackers embed malicious code in ChatGPT prompts, redirecting users to phishing pages that exploit ClickFix to install malware. The campaign targets users searching for AI tools, exploiting trust in ChatGPT. Security researchers warn about the use of AI-generated content to facilitate malware distribution.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-29T20:59:39+00:00 - Category: threat-intel

Original Description: Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

"The highest stage in moral ure at which we can arrive is when we recognize that we ought to control our thoughts."

— Charles Darwin
Source: Bleeping Computer