Interestana
Home/News/Attackers Abuse ChatGPT Custom GPTs for Malware Delivery
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Attackers Abuse ChatGPT Custom GPTs for Malware Delivery

Attackers Abuse ChatGPT Custom GPTs for Malware Delivery

Threat actors are actively abusing OpenAI's Custom GPTs feature within ChatGPT to distribute malware, disguising malicious links as legitimate product offerings. This tactic directs unsuspecting victims to compromised websites that utilize ClickFix lures to deliver malicious payloads. Huntress, a cybersecurity firm, observed this activity in late September 2026, noting it as a new method of exploiting trusted artificial intelligence (AI) platforms. This development follows previous campaigns that have weaponized other features of AI platforms for malicious purposes.

The ClickFix lure, as described by Huntress, is a social engineering technique designed to trick users into believing they are interacting with a legitimate software update or fix. When a user clicks on a link provided by a compromised Custom GPT, they are often redirected to a site that mimics a trusted software vendor or service. This site then prompts the user to download a file, which, instead of providing a legitimate update, installs malware on their system. The specific type of malware delivered in these campaigns has not been detailed, but the use of such lures suggests the potential for a range of malicious activities, including data theft, system compromise, or further network infiltration.

Custom GPTs allow users to create specialized versions of ChatGPT tailored for specific tasks or information domains. This customization capability, while powerful for legitimate use cases, also presents an expanded attack surface for threat actors. By creating a Custom GPT that appears to offer a useful tool or service, attackers can gain the trust of potential victims. The malicious links are then embedded within the GPT's responses or its description, making them appear as part of a legitimate interaction. The ease with which these GPTs can be shared and accessed within the ChatGPT ecosystem amplifies the potential reach of these attacks.

Huntress's observation highlights a growing trend of threat actors leveraging AI technologies for criminal activities. Previously, attackers have been known to use AI for generating phishing emails, creating deepfake content, or developing more sophisticated social engineering tactics. The abuse of Custom GPTs represents a significant evolution, as it integrates malicious operations directly into the conversational AI interface itself. This requires users to exercise increased vigilance when interacting with AI-generated content and links, especially those that appear to offer software downloads or urgent updates. The cybersecurity community is closely monitoring these evolving threats to develop effective countermeasures against AI-powered malware delivery systems.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next