Researchers found a real malware campaign where attackers abused ChatGPT “CustomGPTs” and Google sponsored search results to funnel victims to a fake ChatGPT experience. Victims are shown a fake “Service Availability Notice” and pushed to a “backup domain” that looks like a Cloudflare CAPTCHA, where they’re tricked into copy/pasting commands (ClickFix) that lead to malware installation and a remote access trojan (RAT).
How the Attack Worked
This campaign began with a fake CustomGPT named Plus 5.6, built to look like the real ChatGPT. Victims searching for 'chatgpt' on Google were directed to it through sponsored search results, which gave the fake tool an air of legitimacy before a user ever clicked. Once on the site, the CustomGPT displayed a 'Service Availability Notice' claiming limited availability on the 'primary domain' and pushing users toward a 'backup domain' instead.
That backup domain was designed to look like a Cloudflare CAPTCHA check. Instead of a simple checkbox, it asked users to copy and paste a command to 'verify' themselves, a technique known as ClickFix. Following the instructions led to a malicious MSI installer that deployed a Canon-signed application used for sideloading and persistence, ultimately delivering a remote access trojan (RAT) capable of monitoring activity, capturing audio and video, and exfiltrating data to attacker-controlled infrastructure.
Why It Succeeded
The flow leaned heavily on brand trust. Every step borrowed a name people already recognize, from ChatGPT and Google to Cloudflare and Canon. Each brand on its own looked routine, and stacking them together made the overall chain feel more credible than any single fake page could on its own. The use of sponsored search placement also meant victims encountered the fake tool through a channel they generally treat as safe.
What to Watch For
- Sponsored search results that lead to AI tools like ChatGPT should be treated as unverified until the domain is confirmed.
- Any 'Service Availability Notice' or similar message pushing users to a secondary or 'backup domain' is a strong warning sign.
- A CAPTCHA or verification page that asks you to copy and paste a command is not a real verification step; it is a delivery mechanism for malware.
- Multiple trusted brand names appearing together in one flow (ChatGPT, Google, Cloudflare, Canon) can be a sign attackers are using familiarity to lower suspicion rather than evidence of legitimacy.
Building Resistance
Organizations can reduce exposure by reinforcing a few simple habits. Staff should be reminded that no legitimate website will ever ask them to copy and paste a command to prove they are human, and that this should be an automatic stop sign regardless of how official the surrounding page looks. Encourage employees to verify the real domain of any AI tool before interacting with it, especially when arriving via a sponsored or advertised link. Finally, since researchers found a new CustomGPT linked to the same campaign even after the first was taken down, organizations should treat reporting of suspicious AI tool lookalikes as an ongoing need rather than a one-time fix, and remind staff that look-alike campaigns can reappear quickly under new names.
Key findings
- Campaign active since September; Huntress observed at least 40 infections.
- Attack chain starts via sponsored search results when users search for ‘chatgpt’ on Google.
- Attackers created a CustomGPT named “Plus 5.6” designed to look like the real ChatGPT and interact with victims.
- Victims see a “Service Availability Notice” and are redirected from a “primary domain” to a “backup domain.”
- Backup domain mimics a CloudFlare CAPTCHA and asks users to copy/paste a command to ‘verify’ (ClickFix).
- The flow leads to a malicious MSI that deploys a Canon-signed app used for sideloading, persistence, and delivery of a RAT.
- RAT capability includes monitoring plus capturing audio/video and exfiltrating data to attacker-controlled C2.
- Huntress reported the CustomGPT to OpenAI; it was taken down (as of Sept 25), but a new linked CustomGPT has already been found.
Who’s being targeted
- Commonly targeted roles: All staff, IT helpdesk, Developers/Engineers, Anyone who uses AI tools via the web (ChatGPT users).
- Affected industries: Any industry (end-users searching for ChatGPT/AI tools), Information technology, Professional services, Education.
- Attack channels: website.
- Impersonated: ChatGPT/OpenAI and Cloudflare (brand impersonation).
Red flags to watch for
- A website asks you to copy/paste a command to prove you’re human
- Unexpected redirect to a “backup domain” after searching for ChatGPT
- Brand-stacking (ChatGPT/Google/Cloudflare/Canon) used to build trust
Frequently asked questions
How did attackers impersonate ChatGPT in this campaign?
Attackers created a CustomGPT called Plus 5.6 designed to look like real ChatGPT, then used sponsored search results to direct users searching for 'chatgpt' on Google to it.
What is ClickFix and how was it used here?
ClickFix is a technique where a fake CAPTCHA page asks the user to copy and paste a command to 'verify' themselves, which actually triggers a malicious download leading to a remote access trojan.
What should employees do if a site asks them to paste a command to verify they're human?
They should treat it as a major red flag since no legitimate website will ever ask a user to copy and paste a command to prove they're human, and should close the page and report it.
Was the fake CustomGPT removed?
Researchers reported the Plus 5.6 CustomGPT to OpenAI and it was taken down as of September 25, but a new linked CustomGPT tied to the same campaign has already been identified.
Read the video transcript
You Google “chatgpt,” click the top sponsored result, and it even talks to you like real ChatGPT. But this one’s a fake CustomGPT called “Plus 5.6.” It pops up a “Service Availability Notice” and shoves you to a backup domain that looks like a Cloudflare CAPTCHA. Here’s the hook: the fake Cloudflare page tells you to copy and paste a command to prove you’re human. That ClickFix trick silently pulls down malware and a RAT that can watch, listen, and steal data. If any “ChatGPT” or CAPTCHA page ever asks you to paste a command, stop right there and report it to IT, do not paste anything.