Search results for

All search results
Best daily deals

Affiliate links on Android Authority may earn us a commission. Learn more.

A real ChatGPT page is being used to trick people into installing malware

The dangerous part only appears after ChatGPT has already earned your trust.
By
•

Oct 1, 2026 — 6:07 AM ET

•
•
Open AI ChatGPT logo on phone stock photo 9
Edgar Cervantes / Android Authority
Add Android Authority on Google:
TL;DR
  • Attackers created a fake ChatGPT model called “Plus 5.6” on the real ChatGPT website.
  • It sent users to a fake security check that tricked them into running a malicious Windows command.
  • That command could install malware that could access files, the screen, the webcam, the microphone, and more.

There was a time when spotting a sketchy download meant looking for misspelled websites, strange pop-ups, and other obvious red flags. But that gets much harder when the scam starts on a website you already trust. Security researchers have uncovered a malware campaign that does exactly that, using a real ChatGPT page to convince people they’re dealing with an official OpenAI product before redirecting them to a far more dangerous site.

Researchers at Huntress (via TechRadar) found attackers abusing ChatGPT’s Custom GPT feature to create a bot called “Plus 5.6.” The name was chosen to sound like an official OpenAI model, and because Custom GPTs are hosted on ChatGPT.com, anyone opening the link would see a legitimate ChatGPT address in their browser.

In some cases, Huntress says victims even reached the fake GPT through a sponsored Google Search result for “ChatGPT,” putting the malicious link above regular search results.

Whatever users typed, Plus 5.6 returned essentially the same message. It claimed ChatGPT was having availability problems and offered a “backup domain.” That link opened a Google Sites page dressed up as a Cloudflare security check, where users were instructed to copy a command and paste it into Windows.

That fake check used a tactic known as ClickFix. Instead of exploiting a software bug, ClickFix tricks you into doing the dangerous part yourself by presenting a fake problem and then offering a supposed fix. Here, victims were told to copy a command and paste it into Windows, making it appear to be a routine verification step.

And that’s where the real damage began. Running the command started a hidden chain that eventually installed a remote-access trojan, or RAT. In simpler terms, the malware can give an attacker extensive control over the PC, including the ability to view the screen, search files, use the webcam and microphone, capture system audio, and install more malware.

Huntress investigated at least 40 incidents connected to the Google Sites domain, but it could only confirm that two infections started through the malicious Custom GPT. OpenAI allegedly removed one GPT on September 25, but researchers discovered another linked to the same campaign two days later.

This isn’t the first time scammers have found ways to piggyback on the trust people place in AI services. Earlier this year, fake stores appeared in ChatGPT shopping recommendations, exposing shoppers to potential fraud. Researchers have also spotted Android malware using Gemini to change its behavior while running. But the most unsettling part is that nothing looks especially suspicious at first, which is exactly what makes campaigns like this harder for everyday users to spot before it’s too late.

Follow

Thank you for being part of our community. Read our Comment Policy before posting.