Fake ChatGPT ‘Outage’ Lures Users Into Malware

ZDNet Security · Medium sophistication
Last updated October 5, 2026

Attackers are using sponsored Google ads to route people to a malicious “custom GPT” that looks like ChatGPT, even while the user is logged in on the real ChatGPT domain. The fake GPT displays a convincing “service availability” message and pushes a link to a “backup domain” that ultimately instructs victims to paste and run a PowerShell command, installing malware.

How the Attack Worked

This scam begins with a sponsored Google search result for ChatGPT. Instead of landing on the real ChatGPT product, victims are routed to a custom GPT, a user generated, specialized version of ChatGPT that displays a canned Service Availability Notice. The message claims limited availability on the primary domain and offers a link to a backup domain or an upgrade option.

Clicking the link leads to a free site hosted on Google Sites, which is not an actual ChatGPT domain. There, victims encounter a fake Cloudflare verification step that instructs them to paste and run a command in Windows PowerShell. Running that command installs malware on the victim's computer.

Why It Succeeded

The lure is effective because victims can be on the actual ChatGPT domain and already logged into their account, so there is nothing at first to indicate the page is not authentic. The custom GPT also repeats the same canned outage message regardless of what the user types, reinforcing the illusion of a real system notice rather than an interactive scam.

The use of a sponsored ad adds another layer of trust, since many users assume paid search placements are vetted or safe, when in practice sponsored links can be purchased by anyone.

What to Watch For

  • A push toward a non-ChatGPT link, such as a free site hosted on Google Sites
  • A Cloudflare verification step that asks the user to copy, paste, or type commands rather than click a box or button
  • A canned outage or availability message that repeats no matter what the user does
  • Sponsored search results for login or productivity tools appearing before organic results

How to Build Resistance

Employees across all roles, especially those who frequently use AI tools in marketing, sales, HR, engineering, and IT, should be reminded to avoid clicking sponsored links in Google and instead navigate to known tools by typing the URL directly or using a trusted bookmark.

Teams should also understand that legitimate human verification checks, like those from Cloudflare, do not require typing on the keyboard. At most, they ask the user to check a box or press a button. Any prompt that asks for a pasted or typed command should be treated as a red flag and verified with IT or security before taking any action. Reinforcing this distinction can help employees recognize similar lures even if the specific branding or pretext changes.

Key findings

  • The scam begins with a sponsored (paid) Google search result for “ChatGPT.”
  • Victims are led to a malicious custom GPT that always replies with a fake “Service Availability Notice.”
  • The attacker’s link leads to a Google Sites page (not a real ChatGPT domain) with a fake Cloudflare verification step.
  • Victims are instructed to paste and run a Windows/PowerShell command, which installs malware.
  • The lure is convincing because users can be on the real ChatGPT domain and already logged in.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT/Helpdesk, Teams that frequently use AI tools (Marketing, Sales, HR, Engineering).
  • Affected industries: Technology, Professional services, Education, Healthcare, Finance, Government, Any organization with employees using web search and AI tools.
  • Attack channels: website.
  • Impersonated: ChatGPT (via a custom GPT on the ChatGPT domain).

Red flags to watch for

  • User is pushed to a non-ChatGPT link (e.g., a free site hosted on Google Sites)
  • A “Cloudflare verification” asks the user to copy/paste or type commands
  • The page repeats the same canned outage message regardless of what the user types
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake ChatGPT outage scam work?

Attackers use a sponsored Google search result for ChatGPT that leads to a malicious custom GPT. It displays a fake Service Availability Notice and pushes victims to a backup domain hosted on Google Sites, where a fake Cloudflare verification instructs them to paste and run a PowerShell command that installs malware.

Why does this scam seem convincing even to careful users?

Victims can be on the actual ChatGPT domain and already logged into their account, so there is nothing at first glance to indicate the page is not authentic.

What should employees do if a website asks them to run a command?

Never paste and run a command, especially PowerShell or Terminal commands, from a website prompt or popup without verification from IT or security, since a real Cloudflare check never requires typing commands.

How can organizations reduce risk from this type of attack?

Encourage employees to avoid sponsored search links for login or productivity tools and instead navigate using known URLs or trusted bookmarks.

Read the video transcript

You Google “ChatGPT,” click the top sponsored result… and you’re already in the trap. You land on what looks like ChatGPT, even logged into your account. But this is a malicious custom GPT that always replies with a big “Service Availability Notice” and a link to a so-called backup domain. Click that link and you’re on a Google Sites page, not a ChatGPT domain, showing a fake Cloudflare check that tells you to copy a Windows PowerShell command. Paste and run it, and you’ve just installed malware. Here’s the rule: if any site tells you to paste and run a PowerShell or terminal command, stop and contact IT. Real Cloudflare checks never need your keyboard.

Similar attacks

Fake “ChatGPT” GPT Uses ClickFix to Drop RAT

Fake “ChatGPT” GPT Uses ClickFix to Drop RAT

Researchers found a real malware campaign where attackers abused ChatGPT “CustomGPTs” and Google sponsored search results to funnel victims to a fake ChatGPT experience. Victims are shown a fake “Service Availability Notice” and pushed to a “backup domain” that looks like a Cloudflare CAPTCHA,…

September 30, 2026
Fake ChatGPT “Custom GPT” Pushes ClickFix Malware

Fake ChatGPT “Custom GPT” Pushes ClickFix Malware

A real ClickFix campaign abused ChatGPT “Custom GPTs” to impersonate legitimate tools and trick people into running PowerShell commands on their own computers. Victims were funneled from a sponsored Google result to a fake “backup domain” on Google Sites with a Cloudflare CAPTCHA-style prompt,…

September 29, 2026
Fake Custom GPT Pushes ‘CAPTCHA’ RAT Install

Fake Custom GPT Pushes ‘CAPTCHA’ RAT Install

Attackers used sponsored Google search ads to lure people to a malicious ChatGPT Custom GPT (“Plus 5.6”) hosted on the real chatgpt.com site. The Custom GPT redirected victims to a fake Cloudflare CAPTCHA page that instructed them to copy/paste a command into a terminal, leading to installation of…

September 29, 2026
Fake reCAPTCHA “Fix” Spreads MaaS Malware

Fake reCAPTCHA “Fix” Spreads MaaS Malware

Researchers observed real campaigns using compromised WordPress sites to show fake verification/BSOD-style prompts that trick users into running a copied PowerShell command. The technique (ClickFix) was paired with MaaS tools (ErrTraffic and Cruciferra) to deliver malware while attempting to kill…

August 19, 2026
Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Attackers compromised Brevo’s Cloudflare setup using a long-lived API key found in source code, then altered website content at the CDN edge. Visitors were shown fake Cloudflare verification prompts to run Windows commands, and logged-in WordPress admins were targeted with a hidden backdoor plugin…

September 22, 2026
Google Doc “Fix” Trick Delivers Malware

Google Doc “Fix” Trick Delivers Malware

A real-world social engineering attempt used a legitimate Google Doc to trick a target into manually running commands that installed malware. The attacker posed as a crypto marketing executive and used a fake “decryption failure” message and a “manual update” button as the lure, leading to an…

September 21, 2026