Home · Entertainment · Oct 1 archive
Malware Campaign Uses Fake ChatGPT Links to Spread Malware
Confirmed
In Short: Security researchers have uncovered a new malware campaign that uses a real ChatGPT page to trick victims into installing malware.

Researchers at Huntress discovered that attackers are abusing ChatGPT’s Custom GPT feature to create a bot called 'Plus 5.6,' designed to mimic an official OpenAI model.
Victims are directed to Plus 5.6 via sponsored Google search results, leading them to a fake GPT page that claims ChatGPT is experiencing availability issues and offers a 'backup domain.
This backup domain opens a Google Sites page disguised as a Cloudflare security check, where users are instructed to copy and paste a command into Windows.
The malware campaign, active since September, exploits the CustomGPT feature of ChatGPT, which allows users to build personalized versions of the AI.
In some cases, the malicious link appears above regular search results, making it more likely for victims to click on it.
The attackers use social engineering to trick victims into running commands on their own machines, a technique known as ClickFix.
The malware can give attackers extensive control over the infected PC, including the ability to view the screen, search files, use the webcam and microphone, and install more malware.
Cofense’s Phishing Defense Center identified a similar phishing campaign spoofing ChatGPT and OpenAI billing alerts on September 18, 2026.
The campaign impersonates AI brands including ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude.
Security researchers warn that thousands of legitimate small-business websites have been compromised to spread this malware trap.
Huntress advises ChatGPT users to be cautious and not to copy and paste commands from unknown sources.
What this adds
This report adds details on how the malware campaign uses social engineering to trick victims into running commands on their own machines.
Researchers have identified a new CustomGPT linked to the same campaign, indicating ongoing threats.
The malware campaign has been active since September, highlighting the evolving tactics of cybercriminals.
Background
Security researchers have uncovered a malware campaign that tricks victims into installing malware using fake ChatGPT links.
What's confirmed
- Researchers at Huntress discovered that attackers are abusing ChatGPT’s Custom GPT feature to create a bot called 'Plus 5.6,' designed to mimic an official OpenAI model.
- Victims are directed to Plus 5.6 via sponsored Google search results, leading them to a fake GPT page that claims ChatGPT is experiencing availability issues and offers a 'backup domain.
- This backup domain opens a Google Sites page disguised as a Cloudflare security check, where users are instructed to copy and paste a command into Windows.
- The malware campaign, active since September, exploits the CustomGPT feature of ChatGPT, which allows users to build personalized versions of the AI.
- In some cases, the malicious link appears above regular search results, making it more likely for victims to click on it.
- The attackers use social engineering to trick victims into running commands on their own machines, a technique known as ClickFix.
- The malware can give attackers extensive control over the infected PC, including the ability to view the screen, search files, use the webcam and microphone, and install more malware.
- Cofense’s Phishing Defense Center identified a similar phishing campaign spoofing ChatGPT and OpenAI billing alerts on September 18, 2026.
- The campaign impersonates AI brands including ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude.
- Security researchers warn that thousands of legitimate small-business websites have been compromised to spread this malware trap.
- Huntress advises ChatGPT users to be cautious and not to copy and paste commands from unknown sources.
What's still developing
- Researchers have also spotted Android malware using Gemini to change its behavior while running.
- Instead of exploiting a software bug, ClickFix tricks you into doing the dangerous part yourself by presenting a fake problem and then offering a supposed fix.
- “Every step of the attack also borrows a brand people already trust, from ChatGPT and Google to Cloudflare and even Canon software. The takeaway is simple. No legitimate website will ever ask you to copy and paste a command to prove you’re human,” the company said.
- This link directs the user to a malicious Microsoft Software Installer (MSI) which is used to deploy a legitimate Canon-signed application the attackers have used to sideload malicious code, this ultimately establishes persistence on the machine and delivers remote access trojan (RAT) malware.
- As detailed in a blog post by Huntress, the attackers manipulated ChatGPT CustomGPTs to impersonate legitimate product offerings and even to interact with victims, to direct them to sites which deliver malware.
- The superstar — and her Scottish fold cat named Olivia Benson — appeared alongside Mariska Hargitay, who plays Olivia Benson on Law & Order: Special Victims Unit, in a pre-recorded sketch that riffed on Hargitay’s hosting duties.
- Authorities also confirmed that at least two of the victims were nationals of Lesotho.
- With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT, said Josh Varden of the Cofense Phishing Defense Center.
- Clicking the payment button first routes victims through a Google API redirect wrapper.
- It then drops them on a lookalike sign-in page copying OpenAI’s real logos and layout.
- The ‘Law & Order: Special Victims Unit’ star won two Emmys herself last week The ‘Law & Order: Special Victims Unit’ star won two Emmys herself last week Mariska Hargitay used her Emmys monologue to joke about her long-running stint on Law & Order: Special Victims Unit.
- She won Outstanding Lead Actress in a Drama Series for Law & Order: Special Victims Unit in 2006 and Best Documentary in 2017 for I Am Evidence.
