Security researchers recently uncovered a campaign where attackers are abusing ChatGPT Custom GPTs to deliver a remote access trojan. The attackers use a technique known as ClickFix, which tricks users into copying and running malicious commands themselves, often disguised as a fix for a technical problem. Once executed, the attack sideloads a malicious DLL file to install the RAT on the victim's machine, giving intruders remote control over the compromised system.
This campaign targets the exact behavior busy staff exhibit every day: trusting familiar looking tools like AI chat assistants and following what looks like a helpful troubleshooting step. A single paralegal or attorney clicking through a ClickFix prompt could hand an outside party remote access to a machine holding client files, trust account records, or privileged communications.
Rule 4-1.6 requires attorneys to make reasonable efforts to prevent unauthorized access to client information. A RAT installed through a trusted AI tool is precisely the kind of unauthorized access this rule exists to prevent. Recommendation 25-1 pushes firms toward documented cybersecurity assessments, and this incident is a clear reminder that "reasonable efforts" now must account for AI enabled attack paths, not just traditional phishing.
This is exactly the kind of gap ArisGate closes for solo and small Florida law firms, the space between a new attack technique and a documented, defensible response. We help firms translate incidents like this into practical safeguards and audit ready documentation. Schedule a free security audit with ArisGate today and find out where your firm stands.