www.darkreading.com 30 Sept 2026, 21:25 UTC

Attackers Abuse OpenAI’s Trusted Domains to Deliver RAT Malware

Attackers Abuse OpenAI’s Trusted Domains to Deliver RAT Malware
CyberSIXT Evidence Panel Source marked as original reporting

A new ClickFix-style campaign is abusing legitimate domains tied to OpenAI and Google to deliver a remote access Trojan (RAT) via malicious Custom GPTs. Researchers from Huntress have described attackers creating Custom GPTs that imitate real ChatGPT offerings and directing victims to a malicious site through OpenAI’s trusted web infrastructure. Visitors encounter a prompt designed to persuade them to run a PowerShell command, which then downloads an MSI payload and starts a multistage infection. Huntress reports two such Custom GPTs being used in this manner, and the campaign has affected dozens of users to date.

The infection chain relies on a blend of social engineering and trusted branding. After the PowerShell step, the MSI abuses a legitimate, Canon-signed application to sideload malicious DLLs. One DLL decrypts and executes an encrypted loader hidden in a WAV file, which then decrypts and runs the RAT from an encrypted storage file. A second variant uses a different carrier but a functionally similar loader and signed component.

The RAT’s capabilities include stealing data, enabling hidden remote desktop sessions, turning on cameras and microphones, and creating new user accounts, effectively giving attackers a foothold across the network. Huntress notes that many compromised machines subsequently see further malware downloaded, including payloads to harvest browser data and map the endpoint.

In response, the firm emphasises recalibrated awareness training to warn users against executing commands just because a prompt appears on a trusted domain. Dark Reading has sought comment from OpenAI.

View full article

Article by CyberSIXT