Someone on your network followed a custom GPT, pasted a “verification” command, and installed a remote access trojan. The browser tab said OpenAI. The next request looked like Google. Your firewall scored both as routine and moved on. This week’s cybersecurity story is that simple: ChatGPT’s own storefront became a RAT delivery desk, and the click already happened on a domain you allow everywhere.
The FTC confirmed it is investigating OpenAI and Anthropic over possible risks to consumers. That probe will not remove the implant your helpdesk just ran.
Your Cybersecurity Stack Trusted the Storefront
Custom GPTs sit on a brand you already exempted from the ugly fights: SSL inspection, URL filtering, the quarterly “do we block this SaaS” meeting. Attackers noticed. Reporting this week describes a ClickFix-style campaign that wraps the usual paste-and-run trick in a ChatGPT conversation, then walks the victim onto legitimate OpenAI and Google hosts so every reputation feed you pay for stays green.
Threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
You already know the mechanic. Fake check. Run dialog. Clipboard. Execute. The wrapper is what changed. The user thinks they are setting up an assistant, clearing a CAPTCHA, or keeping a tool the company told them to try. Threat detection that still keys on “unknown domain plus PowerShell” stays quiet. The domain is known. The user is known. The parent process is a browser you allow on every VLAN.

Call that what it is: a defense in depth failure at the layer vendors keep describing as solved. Edge threat-protection still earns its keep against random drive-by hosts. It does not score a chatgpt.com page that tells a person to run code. If your SOC still files OpenAI traffic under productivity, you have a classification bug, not a coverage gap. Treat AI chat as an instruction channel that can reach local execution.
Bruce Schneier has been needling the press over what he calls genie behavior: systems finishing jobs in ways the prompter did not intend, while headlines reach for “rogue” and “hacked.” A malicious GPT is more ordinary than that. A person built the lure. A person followed it. The product supplied the trusted skin. If your cyber security program still parks this under “AI risk” as a research theme, you are late. It is commodity social engineering with a better referrer header.
Google’s involvement is doing real work for the attacker. Users hesitate on a random .xyz. They do not hesitate on a Google property they use for mail, docs, and login all day. Your proxy categories probably bundle those hosts into the same allow group as your IdP. That grouping is now part of the attack path. Split “identity provider” from “everything else with a famous certificate” or you will keep blessing the lure.
Security Hardening Has to Follow the Click
You cannot patch a custom GPT the way you patch an appliance. You can make the paste fail, and you can make the next process loud enough that incident response starts on the same shift.
Do this on the clock, then keep it in the runbook:
- Pull 48 hours of proxy, DNS, and browser history for ChatGPT, custom GPT, and adjacent Google destinations, then join those timestamps to process trees that spawned PowerShell, cmd, mshta, wscript, or rundll32 within minutes of the visit. Isolate anything that matches before you debate intent.
- Run host-compromise incident response on those endpoints: credential rotation for the user and any local admins, persistence checks, and outbound C2 hunts. A “please don’t paste commands” ticket is not containment.
- Block the specific GPT identifiers and payload hosts you recover, even when the first click was on openai.com. Reputation for the parent brand is not an allow rule for every object under it.
- Put enterprise AI tools in a browser isolation or VDI lane with clipboard limits so ClickFix is a failed paste instead of a completed install. Pair that with application control or attack-surface reduction so a helpdesk paste cannot become SYSTEM.
- Add a proven “AI domain then living-off-the-land binary” analytic and test it. If the RAT starts spraying VPN, RDP, or SSH, fold those sources into brute-force lockouts and your ipban list. IPBan Pro is one way to autoban that noise on Windows jump hosts; any equivalent works. Ban the scanners. Kill the implant first.
If you have ChatGPT Enterprise or a comparable tenant control, shut the public GPT store for roles that do not need it, and allowlist the assistants legal and engineering actually approved. That is security hardening you can do without waiting for a model vendor to invent a new safety slide. Consumer ChatGPT in a staff browser is an unmanaged execution coach. Treat it like one in procurement and in logging.
Tabletop the messy version. The user did what the prompt said because the UI looked official. Your IR lead will want to talk about awareness. Let them, after the host is imaged and the tokens are dead. Awareness did not stop ClickFix last year either. Constrained execution and a hunt that assumes trusted SaaS can still be the lure will.
A Consumer Probe Will Not Clean Endpoints
An FTC spokesperson confirmed the OpenAI and Anthropic inquiry and declined to say more. Consumer protection cases move on press cycles. Your incident response clock moves on child processes. Waiting for a finding, a fine, or a model-card rewrite is how persistence ages into “we thought it was a browser session.”

This is a bad look for the conference circuit. Microsoft’s Ignite preview this week sells an AI-first platform that covers identities, devices, data, clouds, and the agents sitting next to your people. Read it as calendar copy. The operational fact is your people are already inside those products, and attackers are using the same household names as a delivery path. You do not need that stack to start treating a ChatGPT click as a possible install.
Schneier wants reporting that keeps responsibility on operators and companies instead of dumping every off-script outcome into the model. Steal that framing for your post-incident writeup. The staffer who pasted the command followed a designed prompt. The designer is the adversary. The product made the adversary look like help. Your job is to assume that pattern keeps working until the execute step breaks.
chatgpt.com is in scope for host-compromise IR today. So is the Google host that made the session feel normal. Put both in the playbook before the next custom GPT learns your users’ muscle memory.
Sources
- Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
- FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
- I Want Better Reporting on AI Genie Behavior
- Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
