Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Vendors and products
- Reported by
- 1 outlet
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-30 21:25 UTC
Related stories
- Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
The Hacker News · 2026-10-02
- Microsoft says threat actors are ahead in the early AI race
BleepingComputer · 2026-10-01
- OpenAI software attempted to secretly scrape data from dozens of prominent websites
The Record · 2026-10-01
- Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
The Record · 2026-10-01
- ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
The Hacker News · 2026-10-01