Report reveals fake ChatGPT model hiding malware
Attackers hosted a 'Plus 5.6' Custom GPT on ChatGPT.com, then sent victims to a ClickFix malware page
Nothing about the address looked wrong. The link opened on ChatGPT, the real site, and the bot inside called itself "Plus 5.6." That was the trap.
Huntress researchers have found that the threat actors exploited the ChatGPT Custom GPT feature to construct the bot. The name was chosen to make it look like an official OpenAI product. The Custom GPTs operate on ChatGPT, which means that you will be seeing a legitimate web address from your browser.
The victims could land there through the Google-sponsored link for "ChatGPT" appearing even before the standard Google results.
Enter any prompt, and Plus 5.6 gave almost identical responses, saying that ChatGPT was experiencing availability issues and that this was the "backup domain".
Clicking on that link redirected you to the fake Cloudflare security check on Google Sites. The victim was asked to copy a particular command and enter it in Windows.
This is ClickFix. It does not take advantage of any software bug. The victim commits the dangerous act himself/herself because it seems like a standard procedure.
Running the command starts a hidden chain that installs a remote-access trojan. The attacker can watch your screen, search your files, use your webcam and microphone, capture system audio and install more malware.
Huntress investigated at least 40 incidents tied to the Google Sites domain. It could confirm only two that began with the malicious Custom GPT.
OpenAI reportedly removed one GPT on September 25. Researchers found another linked to the same campaign two days later.
Scammers have already used AI platforms' credibility this year, with fake stores turning up in ChatGPT shopping recommendations. Expect more of it. If any page asks you to paste a command into Windows, close it, however trusted the site that sent you there.
-
Broadcom’s $42 billion deal with Anthropic: Key details to know
-
Is your job next? Ford CEO on AI, spreadsheet work
-
X likely to plan new four-tier Grok subscription
-
Chinese hackers impersonate US official to gather intelligence on AI policy
-
Australia's Anika Wells makes Time100 list after social media ban fight
-
Study reveals Germany's edge in humanoid robot parts
-
Is WhatsApp's new navigation bar better without labels?
-
Google launches Gemini 4 Argon as its new frontier model