Attackers are abusing “Custom GPTs” and related promotions to trick users into visiting malicious sites that deliver remote access trojans (RATs). Multiple reports describe campaigns that use ClickFix-style interactions—where users are directed to unexpected or deceptive steps on the destination page—to ultimately lead to malware delivery.
The activity involves impersonation and distribution tactics that make the lure appear legitimate. According to reporting, attackers create or promote Custom GPT variants that present themselves as product or service offerings, then guide users to harmful destinations. One outlet notes the activity is observed in late September 2026, and frames the campaign as a broader pattern of threat actors weaponizing trusted AI platform features.
Outlets differ in emphasis and specifics: one focuses on sponsored Google search results pushing users toward malicious domains, while others highlight the misuse of legitimate-looking domains tied to OpenAI and Google and the disguise of the payload as an offer. Despite these angle differences, the core mechanism—Custom GPT-based social engineering combined with ClickFix lures for RAT deployment—is consistent across coverage.