Threat Actors Weaponize Malicious Custom GPTs to Deliver Remote Access Trojans via ChatGPT
A new ClickFix-style attack exploits legitimate OpenAI and Google domains to deceive unsuspecting users. Attackers create malicious custom applications…
Train users on the risks of downloading or executing files from unknown custom GPTs. Deploy controls for file downloads and execution, and monitor endpoints for suspicious activity. Consider restricting access to unverified OpenAI applications in corporate environments.