ScamLens
Technicaldark reading · 9/30/2026

Malicious Custom GPTs Deliver RAT via ChatGPT and Domain Spoofing

This is a standalone intelligence detail page built for indexing and citation, with the summary, linked domains, and next verification paths in one place.

Quick Answer

Threat actors abuse legitimate OpenAI and Google domains in a ClickFix-style campaign to distribute Remote Access Trojans (RATs). Users are deceived through malicious custom GPTs, exploiting trust in legitimate platforms to deliver malware.

2 linked domains surfaced
Tagged as Phishing / Tech Support Scam
Intelligence grade actionable

dark reading

Source

MEDIUM

Importance

2

Linked Domains

0

Linked Addresses

AI Summary

Threat actors abuse legitimate OpenAI and Google domains in a ClickFix-style campaign to distribute Remote Access Trojans (RATs). Users are deceived through malicious custom GPTs, exploiting trust in legitimate platforms to deliver malware.

Scam Labels

PhishingTech Support Scam

Linked Domains