Huntress researchers report that attackers are abusing ChatGPT's Custom GPT feature to impersonate AI products and trick people into installing a sophisticated remote access trojan (RAT). The finding is a useful reminder that a familiar, trusted interface can carry a threat. This Custom GPT malware remote access trojan campaign does not rely on a flaw in your computer. It relies on you believing the chat window in front of you.
How the Custom GPT malware lure works
Custom GPTs are tailored versions of ChatGPT that anyone can build and publish. That openness is what makes the feature useful, and it is also what attackers are exploiting. According to Huntress, the threat actors build Custom GPTs that pose as legitimate AI products, then steer visitors toward installing malware.
The source article is brief on technical specifics, so it is worth separating what is confirmed from what is not. The confirmed part is the core pattern: a Custom GPT impersonates an AI product, and the victim is persuaded to install a RAT. Other coverage of the same activity describes the lure reaching people through sponsored Google results and using ClickFix-style tactics, where a user is coaxed into running PowerShell commands themselves. That detail comes from secondary reporting, so treat it as context rather than the final word.
The common thread is that the victim does the work. Instead of exploiting software, the attacker supplies a convincing story and a set of instructions, and the user carries them out.
What a remote access trojan can do to your device
A remote access trojan gives an attacker a hidden way to control a machine from afar. Once one is running, the person behind it can often act as if they were sitting at your keyboard. Security vendors commonly describe RAT capabilities as including:
- Viewing and copying files
- Monitoring activity and reading messages
- Capturing keystrokes and credentials
- Activating a webcam or microphone
- Installing additional malware
Exactly which of these a given RAT supports depends on the strain, and Huntress describes this one as sophisticated. The practical takeaway is that a RAT infection is rarely a minor nuisance. Because it can run quietly, you may not notice anything wrong while saved passwords, work documents, and session data are exposed.
For anyone using a work laptop, the stakes extend beyond personal data. A compromised device can become a foothold into company accounts and systems.
Why trusted AI platforms make convincing delivery channels
People have spent years learning to distrust strange email attachments and unfamiliar download sites. Far fewer have learned to question a chat interface that lives on a well-known AI platform. A Custom GPT appears inside the same environment people already use for drafting emails or summarizing documents, and that context lends borrowed credibility.
There are a few reasons this works well for attackers:
- Familiar surroundings. The page looks and feels like the real service, so suspicion stays low.
- Conversational pressure. A chatbot can answer objections, sound helpful, and walk a person through steps one at a time.
- Brand impersonation. Naming a Custom GPT after an AI product people want to try gives the lure a ready-made audience.
This fits a wider pattern of AI tools being pulled into the attacker toolkit. For broader context, our coverage of Anthropic's 154-page report on AI-built malware and zero-days looks at how AI misuse is evolving beyond a single trick.
How to vet AI tools before installing anything
You do not need to avoid AI tools. You need a few habits that interrupt this kind of attack.
- Question any request to download or run software. A chat assistant that asks you to install a program, or to paste commands into PowerShell or a terminal, deserves immediate suspicion.
- Go to the source directly. If you want a specific AI product, type the official address yourself or use the vendor's own channels rather than clicking a sponsored search result.
- Check who built it. A Custom GPT is published by an individual or organization, not necessarily by the brand in its name. Look at the creator details before trusting it.
- Never paste commands you do not understand. If you cannot explain what a command does, do not run it.
- Keep security software current. Endpoint protection can catch a payload even when the lure works.
What This Means For You
If you use ChatGPT, the platform itself is not the problem. The risk is that any public Custom GPT can say anything, including claiming to be something it is not. Being on a trusted site does not make the content trustworthy.
If you have already followed instructions from a Custom GPT to install software or run commands, disconnect the device from the network, run a full scan with reputable security software, and change important passwords from a different, clean device. If it is a work machine, tell your IT or security team right away. They can investigate in ways an individual cannot.
The takeaway
The Custom GPT malware remote access trojan campaign Huntress describes shows how attackers adapt to where people already place their trust. Treat any AI tool that asks you to download or run software with suspicion, verify the publisher, and reach products through official channels. To see how these threats fit into the larger picture, read our summary of Anthropic's threat intelligence report on AI misuse.




