{"data":{"id":"44709961-79f5-4b8b-a197-7a4423e3d16b","title":"Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures","summary":"Threat actors are abusing ChatGPT Custom GPTs, which are hosted on the legitimate chatgpt.com site, to point victims to a Google Sites page that uses a fake Cloudflare CAPTCHA to trigger a ClickFix attack. The attack leads to a malicious MSI installer that sideloads a rogue DLL through a Canon-signed binary and ultimately runs a remote access trojan, with at least 40 users infected according to Huntress. The trojan can capture camera, microphone and system audio, run remote desktop sessions, and locate its C2 server via DNS-over-HTTPS.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html","publishedAt":"2026-09-30T15:00:15.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["other"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["ChatGPT","ChatGPT Custom GPTs"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-09-30T15:00:15.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}