Malicious ChatGPT Custom GPTs Used to Spread RAT Malware via ClickFix Attack

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Threat actors exploited ChatGPT's Custom GPT feature to impersonate legitimate products and lure users into installing remote access trojan (RAT) malware. At least 40 victims were infected after interacting with malicious Custom GPTs, which directed them to fake sites and prompted harmful code execution. The attacks leveraged sponsored Google ads and chatgpt.com.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of an AI system (custom GPT bots on ChatGPT.com) in a malicious way to trick users into installing malware. The AI system's misuse directly caused harm by enabling attackers to gain unauthorized access to victims' devices, violating their privacy and security. This fits the definition of an AI Incident because the AI system's use directly led to harm (privacy violations, unauthorized control of devices). The campaign affected dozens of users, confirming realized harm rather than just potential risk. Therefore, the event is classified as an AI Incident.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rightsEconomic/Property

AI system task:
Interaction support/chatbotsContent generation


Articles about this incident or hazard