A sponsored Google result for ChatGPT led some users to “Plus 5.6,” an attacker-created Custom GPT hosted on the real ChatGPT website. The GPT claimed the service was unavailable and sent visitors to a supposed backup page on Google Sites. There, a fake Cloudflare CAPTCHA tried to persuade Windows users to run a PowerShell command that installed a remote-access trojan.
3
6
17
How the “Plus 5.6” lure worked
The campaign combined familiar, legitimate-looking services to build trust:
- A sponsored search result directed people searching for ChatGPT to the attacker-created GPT. A genuine ChatGPT domain did not mean the GPT itself was official.
3
6
- A false service notice told visitors that ChatGPT was having availability problems and pointed them to a purported backup site.
6
12
- A fake Cloudflare check on the Google Sites page instructed visitors to copy and run a PowerShell command. This is a ClickFix-style trick: instead of exploiting a software flaw, it gets the person to run the harmful command themselves.
3
17
- A malware installation followed. Huntress describes the command as starting a multi-stage infection chain that downloads a malicious MSI and installs a remote-access trojan on Windows.
17
Some coverage calls the trojan “@input,” but Huntress’s supplied campaign summary describes it more generally as a remote-access trojan. The exact malware label is therefore best treated as a reported name, not as independently confirmed here.
8
17
What researchers observed—and what remains unclear
Huntress identified two Custom GPTs linked to the campaign. It reported responding to at least 40 incidents associated with the specific Google Sites domain; two of those incidents were confirmed as coming through a Custom GPT instance.
14
17 That distinction matters: the 40 incidents were tied to the domain, not all necessarily confirmed as infections caused by the GPT lure.
OpenAI removed one malicious GPT, but a second variant was reported to have appeared and remained live two days later.
1 The reporting supplied here does not establish what action Google took on the ads, or whether all ads and related pages were removed.
This was not the first reported abuse of a trusted AI-hosting surface. Huntress previously described a separate campaign involving a malicious Claude Artifact hosted on the legitimate Claude site that affected more than 29 organizations.
18 That earlier case is a related example of how attackers can misuse familiar platforms as part of a lure; it does not establish that the incidents shared an operator or infrastructure.
Warning signs and ways to avoid the scam
- A sponsored result is an advertisement, not an endorsement. Check what the link leads to, even if it opens on a familiar service.
3
6
- A real platform can host attacker-created content. Look closely at whether a GPT is an official product or a user-created bot; a legitimate domain alone does not verify its claims.
3
17
- Do not run commands provided by a CAPTCHA or an unexpected website. A request to open Windows Run, paste text, or execute PowerShell is a serious warning sign—not a normal verification step.
3
8
17
- Navigate to ChatGPT directly using a bookmark or an address you type yourself, rather than relying on an unexpected sponsored result.
- If you already ran the command, stop using the affected computer for sensitive activity and contact a trusted IT or security professional promptly.