A new ClickFix variant uses browser cache to bypass Windows Run character limits, while Ukrainian CERT-UA reports a surge in fake CAPTCHA attacks targeting Windows users via compromised sites.
A new scam uses sponsored Google ads to direct users to malicious Custom GPTs on the legitimate chatgpt.com domain. These fake interfaces display a 'Service Availability Notice' and link to a Google Sites page mimicking a Cloudflare check. The page instructs users to run PowerShell commands, installing a remote access trojan (RAT) via signed applications. Huntress confirmed at least 40 incidents, with OpenAI removing the first instance by September 25, 2026. Experts warn that trusted domains like ChatGPT and Google are being abused to bypass security awareness, urging users to never paste commands into terminals as a verification step.
Threat actors are abusing ChatGPT Custom GPTs to deliver remote access trojans (RATs) through ClickFix lures. Huntress identified a campaign where malicious GPTs, hosted on the legitimate chatgpt.com domain, redirect users to fake Cloudflare CAPTCHA pages. These pages trick victims into executing PowerShell commands that install malware. The infection chain uses signed binaries to sideload malicious DLLs, ultimately deploying a RAT capable of data theft, surveillance, and network persistence. At least 40 users have been infected, with the initial entry point often being sponsored Google ads for 'chatgpt'.
Security firm Netskope identified a widespread campaign using Google Ads to deliver fake security warnings that lock browsers on Windows and Mac devices. The ads, which appeared on major sites like maps and weather platforms, tricked users into calling fraudulent support lines. While Google is investigating the violation of its policies, experts note that the ads exploited technical loopholes to evade detection.
A new variant of the MacSync macOS stealer uses public iCloud calendar events to hide command payloads, adding a Finder-disguised backdoor and server-side decryption to evade static analysis.
Researchers warn of RatHat, an Android malware linked to Chinese actors that uses AI to navigate the device in real time, overlay apps, and capture credentials. It tricks users into installing a fake legitimate app, requests accessibility permissions, enables Wireless Debugging, and records touch inputs to steal passwords and MFA codes. Infections occur via social engineering, and the only way to remove it is a factory reset.
A new Android malware named RatHat uses AI-powered capabilities to secretly gain admin-level control by masquerading as a legitimate app, abusing accessibility permissions and Wireless Debugging to escalate to ADB Shell, then installing an AI-assisted agent and a proxy to exfiltrate data. It targets popular financial apps (WeChat Pay and Alipay) with 162 infected apps detected so far, and can silently capture screen content, usernames, passwords, 2FA codes, touch input to reproduce PINs and patterns, and SMS messages; removal is difficult because the malware hides files and can reinstall after uninstalling, making a full factory reset the recommended fix. Prevention includes avoiding suspicious links, verifying Play Store authenticity, and denying accessibility permissions; Malwarebytes on Google Play can help detect it.
A new Android malware named RatHat uses an AI-powered UI automation subsystem to remotely control compromised devices via Accessibility permissions, enabling actions such as enabling Developer Options, ADB shell access, keylogging, credential-stealing overlays, SMS/OTP interception, and a persistent reverse-proxy tunnel; it can restore itself after removal and even intercept uninstall prompts. Linked to Chinese actors per Zimperium, RatHat spreads via malvertising, phishing, and APKs from outside Google Play, and includes anti-analysis tricks to hinder detection. Users are advised to avoid sideloaded APKs, revoke unnecessary Accessibility permissions, and regularly scan with Play Protect.
Mantax Otax is a new Android malware strain that combines ransomware and spyware functions to encrypt files, steal data, and harass victims. It spreads via malicious APKs hosted outside Google Play, requests Accessibility permissions to gain control, and fetches its C2 domain from GitHub, handling commands through Firebase or WebSockets. The ransomware targets devices on Android 9 and older, encrypting files with a C2-provided AES key, appending .enc, and replacing images with ransom notes while enabling full-screen chats to negotiated payments. Beyond encryption, Mantax Otax can steal lock-screen PINs, SMS/OTP, call logs, contacts, Google account data, and location, plus exfiltrate WhatsApp/Telegram chats and capture screenshots, videos, and photos (even streaming them). Misconfigurations exposed attacker communications via Firebase. Play Protect blocks Mantax Otax; users should avoid off-store APKs, deny questionable Accessibility permissions, and install only reputable publishers.
Researchers at Calif say they used AI to develop WeWorm, a zero-click worm that hijacks a WeChat account during an incoming call by exploiting a memory-bug in WeChat’s calling stack, then automatically calls the victim’s contacts to spread. The attacker must be on the victim’s friend list, and once in, can read and send messages and perform actions as the owner. Tencent says the flaw was fixed and that no users were reported affected; no CVE or public advisory has been released. The team built the exploit in roughly two weeks after bug discovery, with a demo in August, and plans a full analysis for a conference. The case underscores AI-enabled attack risks and comes as EU cyber-resilience rules push for disclosure requirements.
ClickFix has become a mainstream malware delivery method that tricks users into pasting a single malicious command from a fake CAPTCHA overlay on compromised sites, bypassing code-signing and Gatekeeper protections and enabling infections on Windows and macOS; campaigns span Google Sheets-based control and blockchain-hosted infrastructure, with about 5,400 sites involved, but defenders like BlockBlock and uBlock offer mitigations, and researchers urge awareness over user-blaming.
Security researchers describe JSCeal, a sophisticated compiled V8 JavaScript malware that harvests credentials, keystrokes, and screenshots, and can reconstruct stolen cookies to replay browser sessions and bypass Google authentication. It uses multi‑layer obfuscation and a proxy-based traffic interceptor to modify requests for crypto services, and is delivered via malvertising campaigns (including SourTrade) that assemble the final payload inside the victim’s browser, signaling active development and broad targeting of Chromium-based browsers across 12 countries in 25 languages.
Security researchers warn that streaming devices like the SuperBox S7 Pro can be hijacked to form residential proxy networks, letting attackers route illicit traffic through home connections. Malicious apps can be remotely installed with root access, the Android ADB port exposed and unprotected, bypassing protections and turning devices into nodes for botnets or DDoS networks; the problem is widespread, and users are urged to disconnect and discard such devices.
Google warns of a fake Chrome update prompt that can appear on normal websites and push malicious downloads, linked to a hijacked extension (Enable Right Click & Copy - Smart Unlock + OCR) that researchers say was weaponized after acquisition; a broader campaign tied to 19 Chrome/Edge extensions targets users with credential theft and other malware. To stay safe, never update Chrome from a webpage prompt—check for updates via Chrome’s About page, review and remove suspicious extensions and their permissions, enable Enhanced Protection, run full antivirus scans, and consider data-removal services to reduce personal information exposure; restart the browser after removing extensions and monitor for further signs of hijacking.
A circulating 113GB GTA 6 PC ISO is fake and loaded with malware designed to disable Windows Defender and other security software; analysts warn fans not to trust unofficial downloads amid GTA 6 hype as the November release approaches.