Home › New Malware Campaign Exploits ChatGPT to Trick Users

New Malware Campaign Exploits ChatGPT to Trick Users

10/1/2026
New Malware Campaign Exploits ChatGPT to Trick Users

In an alarming development, security experts have uncovered a malware campaign that exploits the trust users place in reputable websites. This campaign uses a legitimate ChatGPT page to mislead individuals into downloading dangerous software, showcasing how cybercriminals are evolving their tactics.

The Deceptive Use of ChatGPT

Researchers from Huntress recently revealed that attackers have misused the Custom GPT feature of ChatGPT to create a bot named “Plus 5.6.” This name was deliberately chosen to mimic an official OpenAI model, thereby luring unsuspecting users. Since Custom GPTs are hosted on the official ChatGPT website, victims are often unaware that they are interacting with a malicious entity.

How the Scam Works

In some instances, users have encountered the fake GPT through sponsored Google search results for “ChatGPT,” which placed the malicious link above legitimate results. Upon interaction, Plus 5.6 would inform users of supposed availability issues with ChatGPT and suggest a “backup domain.” This link redirected victims to a Google Sites page masquerading as a Cloudflare security check.

The ClickFix Tactic

The Google Sites page employed a method known as ClickFix, which tricks users into executing harmful actions. Instead of exploiting software vulnerabilities, it presents a fabricated problem that encourages victims to take the dangerous step themselves. Users were instructed to copy a command and paste it into their Windows system, making it appear as a standard verification protocol.

Consequences of the Infection

Once executed, the command initiated a hidden process that ultimately installed a remote-access trojan (RAT). This malware grants attackers extensive control over the infected computer, allowing them to view screens, search through files, utilize webcams and microphones, capture system audio, and even install additional malicious software.

Huntress has tracked at least 40 incidents linked to the Google Sites domain but confirmed that two infections stemmed from this malicious Custom GPT. While OpenAI reportedly removed one GPT on September 25, researchers found another related to the same campaign just two days later.

Previous Scams and Increased Vigilance

This incident is not an isolated case; scammers have previously exploited the credibility of AI services. Earlier in the year, fraudulent stores appeared in ChatGPT shopping recommendations, putting consumers at risk of scams. Researchers have also identified Android malware leveraging Gemini to alter its behavior while in operation.

What makes this campaign particularly troubling is that it does not exhibit any overt signs of danger at first glance, making it challenging for average users to identify before it's too late. Awareness and vigilance remain crucial in navigating the increasingly sophisticated landscape of online threats.

Source: https://www.androidauthority.com/chatgpt-custom-gpt-malware-scam-3717796/

Read Also

Iklan