Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Fake ChatGPT 'Plus 5.6' bot in Google ads led to webcam-spying malware, Huntress says

A custom GPT on OpenAI's own site sent users to a fake Cloudflare check and a PowerShell command that installed a remote-access tool; a second GPT followed the first.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Sponsored Google results for ChatGPT led to a fake custom GPT called Plus 5.6 hosted on chatgpt.com, Huntress says.
  • 2Users were told to paste a PowerShell command that installed malware able to capture screen, webcam and microphone.
  • 3OpenAI took the first GPT down as of September 25; Huntress found a second one on September 27.

The news

Attackers used sponsored Google search results to send people looking for ChatGPT to a fake ChatGPT model called Plus 5.6, which steered them into installing remote-access malware on Windows computers, security firm Huntress said in a September 28 report.

According to Huntress, victims searched Google for "chatgpt" and clicked a sponsored result that opened an attacker-built custom GPT on OpenAI's genuine chatgpt.com site. Custom GPTs are tailored versions of ChatGPT that users can build and share. This one carried a name designed to pass as a ChatGPT model, was listed as the work of a community builder, and displayed a fake service notice claiming limited availability on the main domain. It told users to upgrade to Plus or keep going through a backup domain.

That backup link opened a Google Sites page dressed up as a Cloudflare (NET) security check. The page told visitors to paste a command into PowerShell, the scripting tool built into Microsoft (MSFT) Windows. The technique, known as ClickFix, persuades victims to run the attacker's command themselves.

Huntress traced an eight-stage infection chain. The command downloaded an installer, used a legitimately signed Canon application to load a tampered file, a trick known as DLL sideloading, and pulled the final payload out of an audio file. The resulting remote access trojan (RAT) can run remote desktop sessions, capture the screen, webcam, microphone and system audio, search files, profile the machine and install more malware. It reaches its operators through encrypted DNS lookups via Cloudflare, Google and Quad9 resolvers, and re-creates its startup entries every 150 to 875 seconds if they are deleted.

Huntress said its security operations center responded to at least 40 incidents tied to the Google Sites page, two of which came through a custom GPT. OpenAI had taken the first GPT down as of September 25, but on September 27 Huntress found a second custom GPT linked to the same campaign, still active when the report went out. That version swapped the Canon application for a Stardock program and hid its loader in a Microsoft NuGet software package, delivering the same RAT.

The numbers

Incidents tied to the Google Sites page (Huntress)
At least 40
Of those, incidents that came through a custom GPT
2
Stages in the infection chain
8
Interval at which malware re-creates deleted startup entries
150 to 875 seconds

Why CEOs should care

For CIOs and CISOs, this campaign defeats a common piece of AI-use advice. Staff told to use ChatGPT only on chatgpt.com would have been on the real site, talking to a GPT the attackers built. Policies should name how employees reach approved AI tools, such as a bookmark, a managed app or single sign-on rather than search ads, and which custom GPTs are allowed. They should also state plainly that no AI tool or website will ever need someone to paste a command into PowerShell or the Windows Run box.

Security teams can act on Huntress's indicators now: PowerShell silently launching an installer from a temporary folder, Canon or Stardock programs running from odd folders under the user's local AppData directory, and startup entries and scheduled tasks with identical names that reappear after deletion. Ask whether standard users need PowerShell at all, and ask your endpoint security vendor to confirm it detects this chain.

For CFOs and boards, the concern is what a RAT with remote desktop, webcam and microphone access could reach on a finance or executive laptop: payment systems, deal documents and meetings. Ask how many employees use personal AI accounts outside company controls, and whether browsers are managed tightly enough to block pages reached through ads.

The bigger picture

The lure lived on trusted ground at every step: a Google ad, OpenAI's own domain, a Google Sites page and a copy of Cloudflare's check screen. Web filters that allow those domains by default will not stop it, which moves the burden to user training and endpoint detection. Takedowns also lag: a replacement GPT surfaced within days of the first removal. SecurityWeek reported Huntress's view that attackers are "finding success in this specific abuse."

What’s next

Watch whether OpenAI adds checks on custom GPTs that imitate its own model names, whether Google removes the ads and tightens review of search ads for AI brands, and whether Huntress or others tie more incidents to the second GPT.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

HuntressOpenAIChatGPTGoogleClickFix

Earlier coverage of OpenAI

All OpenAI coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.