Fake ChatGPT "Plus 5.6" model on chatgpt.com spreads a trojan

Searching Google for "chatgpt" and clicking the top ad can take you to the real chatgpt.com domain. It can still end with a remote access trojan on your PC. Security firm Huntress described a campaign on September 28 in which attackers built a Custom GPT called "Plus 5.6" and promoted it with paid Google ads. Custom GPTs are tailored chatbots that any ChatGPT user can build and share publicly, and OpenAI hosts them on chatgpt.com. The attack does not rely on a flaw in ChatGPT.
The fake backup domain
The fake model answers every prompt with a service notice. ChatGPT is supposedly running with limited availability, so users should upgrade to Plus or continue on a backup domain. The link leads to a Google Sites page dressed up as a Cloudflare check, which tells visitors to copy a command and paste it into Terminal to prove they are human. This technique is known as ClickFix. The command launches PowerShell, which installs a remote access trojan on the Windows PC in eight stages. The malware hides behind a signed Canon application and an audio file. The attacker can then watch the screen, record the camera and microphone, search files and load more malware.
Huntress counted at least 40 incidents tied to the Google Sites page. In two of them, the victim demonstrably came through the Custom GPT. OpenAI removed the first GPT by September 25 after Huntress reported it, and two days later Huntress found a new one with the same name.
Island counted about 850 ad landings
A second report comes from Island, published on October 1. Its researchers tracked a similar campaign from late May to August 24 with about 850 paid-ad landings, 26 lookalike ChatGPT destinations and 71 Google Ads campaign IDs. Here, too, the lures were Custom GPTs or shared chats on chatgpt.com, and they all gave the same reply: "We are experiencing high traffic now. Continue on our backup domain." On that domain, victims were told to press the Windows key and R, paste the clipboard and hit Enter. Island observed behavior consistent with NetSupport RAT, a legitimate remote support tool that criminals often abuse. Neither company links the two campaigns.
A real domain is no longer proof
The same idea was behind the fake Claude app in July, when a Bing ad led to an Artifact on claude.ai. Attackers value a real domain because security filters let it through and users trust it. OpenAI is retiring Custom GPTs anyway. According to its help center, creation of new GPTs is planned to end on October 26, and existing ones will be retired on December 11 and replaced by plugins. Shared chats, which Island also found being used as lures, remain available.
How to protect yourself
Huntress analyst Jonathan Semon told Dark Reading: "no website, chatbot, support page, or 'verification tool' has a legitimate reason to tell you to paste a command into PowerShell or any Terminal to verify who you are, no matter how polished it looks." If a page asks you to do that, close the tab. ChatGPT never sends you to a backup domain, and OpenAI reports outages on status.openai.com. Open chatgpt.com from a bookmark or the app instead of searching for it, so you never see the ads. If you have already run such a command, disconnect the PC from the internet, run a full antivirus scan and change your most important passwords from another device.





