The scheme can start on the real ChatGPT website, making it particularly difficult to spot
Cybercriminals are using fake versions of ChatGPT to trick consumers into installing malware that can give attackers remote access to their computers.
In some cases, victims arrive at the scam through a Google-sponsored search result and initially land on the legitimate ChatGPT website.
The biggest warning sign is a request to leave ChatGPT and run or paste a command on a Windows computer something consumers should never do to verify themselves.
Consumers searching for ChatGPT need to pay particularly close attention to where their clicks take them.
Security researchers have uncovered a malware campaign that impersonates ChatGPT and exploits some of the most familiar names on the internet including Google and ChatGPT itself to persuade victims that they're dealing with a legitimate service.
Researchers at cybersecurity firm Huntress say attackers created malicious Custom GPTs, which are user-created versions of ChatGPT hosted on the legitimate ChatGPT.com domain. One of them was named "Plus 5.6," apparently designed to look like an official version of ChatGPT.
That distinction is important. The scam does not necessarily begin on a misspelled imitation of ChatGPT.com. A consumer can actually be looking at a page hosted on the genuine ChatGPT website while interacting with content created by a third party.
Huntress said it investigated at least 40 incidents associated with the Google Sites domain used in the campaign and confirmed that two infections originated through a malicious Custom GPT.
How the scam works
In some cases, the attack begins with something millions of people do every day: a Google search.
Researchers at Island found that criminals bought sponsored search ads targeting searches such as "chatgpt." Clicking an ad could take a consumer to an attacker-created Custom GPT hosted on ChatGPT.com.
The fake ChatGPT then claims that the normal service has limited availability and directs the user to a supposed "backup domain." From there, the victim encounters what appears to be a Cloudflare human-verification or CAPTCHA page.
That's where the attack becomes dangerous. Instead of simply asking the user to click a box or identify objects in pictures, the verification page instructs Windows users to open the Run dialog, paste a command, and execute it.
Security experts call this type of attack "ClickFix." Rather than exploiting a software vulnerability, it persuades the victim to execute the attacker's command. Island researchers found that the command used in this campaign downloaded a malicious PowerShell loader and ultimately installed remote-access malware.
Huntress found a similarly elaborate infection chain in which the command downloaded an installer and ultimately deployed a remote access trojan, or RAT. Such malware can allow an attacker to maintain access to the infected computer.
Why this scam may be harder to recognize
Consumers have long been advised to inspect web addresses before trusting a website. That's still good advice, but this campaign demonstrates why it isn't always enough.
The criminals are essentially borrowing the credibility of legitimate services.
Island researchers said the campaign did not depend on a security vulnerability in ChatGPT or Google. Instead, attackers combined paid advertising, attacker-created content on trusted platforms, and social engineering to move victims toward malicious software.
Island said its investigation of the broader operation found about 850 paid-ad landings, 26 lookalike ChatGPT destinations, and 71 Google Ads campaign IDs during a three-month observation period. The company cautioned that those numbers represent campaign infrastructure and traffic, not 850 confirmed infections.
Huntress reported the original malicious Custom GPT to OpenAI, and it was removed as of Sept. 25. But researchers discovered another Custom GPT connected with the campaign two days later, suggesting the criminals were quickly rebuilding their operation.
How to protect yourself
Consumers looking for ChatGPT should avoid relying on sponsored search results when possible and go directly to the service they intend to use. OpenAI identifies openai.com, chatgpt.com, and help.openai.com among its official web properties.
More importantly, consumers should be extremely suspicious of any website or chatbot that says a CAPTCHA, security check, or account verification requires opening Windows Run, PowerShell, Command Prompt, or a Mac Terminal and pasting a command. A normal CAPTCHA doesn't require users to execute computer commands.
Also remember that being on ChatGPT.com doesn't necessarily mean every GPT found there was created by OpenAI. Custom GPTs can be created by third parties. In the Huntress case, the malicious "Plus 5.6" page identified its creator as a "community builder," an important clue that it wasn't an official ChatGPT model.
Consumers who encounter an unexpected request to visit a "backup" ChatGPT website, download software, or paste commands into their computer should close the page without following the instructions.
Anyone who has already followed such instructions should disconnect the computer from the internet, run a trusted security scan, and consider having the device professionally checked.
Because remote-access and information-stealing malware may expose passwords and other credentials, users should also change important passwords from a different, known-safe device.
Photo By CNET
Posted: 2026-10-06 12:14:19









