Skip to main content
CyberReportedMedium
4.8

Threat actors weaponize ChatGPT custom GPTs in ClickFix social engineering campaign

Attackers are abusing ChatGPT's custom GPT feature to impersonate legitimate software and lure users into running malicious PowerShell commands, a novel twist on the ClickFix technique. The campaign leverages trusted AI platforms to lower user defenses, though the full scale and targeting remain unclear. This marks an evolution in social engineering that could broaden the attack surface for enterprise environments.

SecurityWeek4 days agoengCredibility 25%View source

Score Breakdown

Mosaic Score4.8
Model confidence0.5
Significance0.5
Source credibility0.3
Source

Related signals

8 found