Home · Entertainment · Oct 1 archive

Malware Campaign Uses Fake ChatGPT Links to Spread Malware

Confirmed

Entertainment Desk

In Short: Security researchers have uncovered a new malware campaign that uses a real ChatGPT page to trick victims into installing malware.

Hackers Abuse ChatGPT Custom GPTs in ClickFix Attacks: How Malware Is Delivered
YouTube — Radio007

Researchers at Huntress discovered that attackers are abusing ChatGPT’s Custom GPT feature to create a bot called 'Plus 5.6,' designed to mimic an official OpenAI model.

Victims are directed to Plus 5.6 via sponsored Google search results, leading them to a fake GPT page that claims ChatGPT is experiencing availability issues and offers a 'backup domain.

YouTube — Radio007 YouTube

This backup domain opens a Google Sites page disguised as a Cloudflare security check, where users are instructed to copy and paste a command into Windows.

The malware campaign, active since September, exploits the CustomGPT feature of ChatGPT, which allows users to build personalized versions of the AI.

In some cases, the malicious link appears above regular search results, making it more likely for victims to click on it.

The attackers use social engineering to trick victims into running commands on their own machines, a technique known as ClickFix.

The malware can give attackers extensive control over the infected PC, including the ability to view the screen, search files, use the webcam and microphone, and install more malware.

Cofense’s Phishing Defense Center identified a similar phishing campaign spoofing ChatGPT and OpenAI billing alerts on September 18, 2026.

The campaign impersonates AI brands including ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude.

Security researchers warn that thousands of legitimate small-business websites have been compromised to spread this malware trap.

Huntress advises ChatGPT users to be cautious and not to copy and paste commands from unknown sources.

What this adds

This report adds details on how the malware campaign uses social engineering to trick victims into running commands on their own machines.

Researchers have identified a new CustomGPT linked to the same campaign, indicating ongoing threats.

The malware campaign has been active since September, highlighting the evolving tactics of cybercriminals.

Background

Security researchers have uncovered a malware campaign that tricks victims into installing malware using fake ChatGPT links.

What's confirmed

What's still developing

Sources