The news
Attackers used sponsored Google search results to send people looking for ChatGPT to a fake ChatGPT model called Plus 5.6, which steered them into installing remote-access malware on Windows computers, security firm Huntress said in a September 28 report.
According to Huntress, victims searched Google for "chatgpt" and clicked a sponsored result that opened an attacker-built custom GPT on OpenAI's genuine chatgpt.com site. Custom GPTs are tailored versions of ChatGPT that users can build and share. This one carried a name designed to pass as a ChatGPT model, was listed as the work of a community builder, and displayed a fake service notice claiming limited availability on the main domain. It told users to upgrade to Plus or keep going through a backup domain.
That backup link opened a Google Sites page dressed up as a Cloudflare (NET) security check. The page told visitors to paste a command into PowerShell, the scripting tool built into Microsoft (MSFT) Windows. The technique, known as ClickFix, persuades victims to run the attacker's command themselves.
Huntress traced an eight-stage infection chain. The command downloaded an installer, used a legitimately signed Canon application to load a tampered file, a trick known as DLL sideloading, and pulled the final payload out of an audio file. The resulting remote access trojan (RAT) can run remote desktop sessions, capture the screen, webcam, microphone and system audio, search files, profile the machine and install more malware. It reaches its operators through encrypted DNS lookups via Cloudflare, Google and Quad9 resolvers, and re-creates its startup entries every 150 to 875 seconds if they are deleted.
Huntress said its security operations center responded to at least 40 incidents tied to the Google Sites page, two of which came through a custom GPT. OpenAI had taken the first GPT down as of September 25, but on September 27 Huntress found a second custom GPT linked to the same campaign, still active when the report went out. That version swapped the Canon application for a Stardock program and hid its loader in a Microsoft NuGet software package, delivering the same RAT.
The numbers
- Incidents tied to the Google Sites page (Huntress)
- At least 40
- Of those, incidents that came through a custom GPT
- 2
- Stages in the infection chain
- 8
- Interval at which malware re-creates deleted startup entries
- 150 to 875 seconds
Why CEOs should care
For CIOs and CISOs, this campaign defeats a common piece of AI-use advice. Staff told to use ChatGPT only on chatgpt.com would have been on the real site, talking to a GPT the attackers built. Policies should name how employees reach approved AI tools, such as a bookmark, a managed app or single sign-on rather than search ads, and which custom GPTs are allowed. They should also state plainly that no AI tool or website will ever need someone to paste a command into PowerShell or the Windows Run box.
Security teams can act on Huntress's indicators now: PowerShell silently launching an installer from a temporary folder, Canon or Stardock programs running from odd folders under the user's local AppData directory, and startup entries and scheduled tasks with identical names that reappear after deletion. Ask whether standard users need PowerShell at all, and ask your endpoint security vendor to confirm it detects this chain.
For CFOs and boards, the concern is what a RAT with remote desktop, webcam and microphone access could reach on a finance or executive laptop: payment systems, deal documents and meetings. Ask how many employees use personal AI accounts outside company controls, and whether browsers are managed tightly enough to block pages reached through ads.
The bigger picture
The lure lived on trusted ground at every step: a Google ad, OpenAI's own domain, a Google Sites page and a copy of Cloudflare's check screen. Web filters that allow those domains by default will not stop it, which moves the burden to user training and endpoint detection. Takedowns also lag: a replacement GPT surfaced within days of the first removal. SecurityWeek reported Huntress's view that attackers are "finding success in this specific abuse."
What’s next
Watch whether OpenAI adds checks on custom GPTs that imitate its own model names, whether Google removes the ads and tightens review of search ads for AI brands, and whether Huntress or others tie more incidents to the second GPT.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









