Application Security
Cybercriminals Exploit Custom GPTs to Execute ClickFix Campaigns
Attackers are weaponizing personalized ChatGPT models to trick users into executing malicious PowerShell commands.
The Rise of AI-Assisted Social Engineering
Threat actors are increasingly leveraging custom GPTs to facilitate sophisticated ClickFix attacks. By masquerading as legitimate product support or utility tools, these AI models build trust with unsuspecting users before prompting them to perform actions that result in the execution of malicious PowerShell commands. This evolution in tactics showcases how AI can be weaponized to automate the social engineering process at scale.
Strengthening Human and Technical Defenses
To counter these threats, organizations must shift their security awareness training to address AI-integrated social engineering. Users should be educated on the risks of executing scripts provided by AI assistants, regardless of how credible they appear. From a technical standpoint, we recommend enforcing strict PowerShell execution policies and using Endpoint Detection and Response (EDR) solutions to flag or block unauthorized command-line execution that originates from unexpected sources.
แหล่งที่มา: SecurityWeek เผยแพร่ครั้งแรก: Tue, 29 Sep 2026 13:03:35 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: SecurityWeek
เผยแพร่ครั้งแรก: Tue, 29 Sep 2026 13:03:35 +0000
บทความต้นฉบับ: https://www.securityweek.com/hackers-use-chatgpt-custom-gpts-in-clickfix-attacks/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
