Custom ChatGPT variants used to push RAT malware
π Researchers at Huntress found threat actors publishing malicious custom GPTs on OpenAI that steer users to a Google Sites page hosting a fake Cloudflare check and a PowerShell command. If executed, the command installs an MSI that sideloads a modified DLL to deliver a remote access trojan (RAT) with remote desktop, audio/camera capture, reconnaissance and persistence functionality. OpenAI removed one GPT by September 25, but variants persisted; the campaign leverages legitimate ChatGPT hosting to increase credibility and employs an encrypted custom archive to conceal components.