Fake ChatGPT Custom GPT Spreads RAT Malware: How to Stay Safe
Attackers are using fake ChatGPT Custom GPTs to trick users into installing a remote access trojan (RAT), according to security firm Huntress. The campaign reportedly used sponsored Google results for “chatgpt” to promote malicious Custom GPTs named “Plus 5.6.” Users who interacted with the fake GPT were directed to a fraudulent backup website and then shown a fake Cloudflare-style CAPTCHA.
The scam uses a ClickFix technique, where victims are instructed to copy and paste a command into Windows PowerShell. Running the command downloads an installer that abuses a legitimate signed program to load malicious files, with the final payload reportedly hidden inside a WAV audio file. Huntress says the RAT can access a device’s camera and microphone, provide remote desktop access, search files, run additional malware and check for antivirus software. The firm confirmed at least 40 infected users.


For Indian users and businesses, the incident is a reminder that familiar AI brands can also be used as bait. Avoid reaching AI services through unfamiliar sponsored search results, and be especially cautious if a website asks you to paste commands into PowerShell, Run or Terminal. Users should also avoid blindly trusting third-party Custom GPTs that redirect them to external or “backup” websites. Keep operating systems and security software updated, enable multi-factor authentication, and if you have already executed a suspicious command, disconnect the affected device and scan it before changing important passwords from a clean device.
Threats like this show why secure browsing and endpoint protection need to work alongside user awareness. Net Protector Total Security provides real-time protection for PCs and data, including anti-malware, firewall and anti-phishing capabilities. For users looking for stronger web protection, Z Plus Security also includes Zero Day Web Protection and DNS Protection.