The digital landscape is currently facing a sophisticated cyberattack strategy that leverages the popularity of artificial intelligence to compromise user devices through a combination of search engine manipulation and social engineering. Security researchers and users have recently identified a highly convincing scam targeting individuals seeking access to ChatGPT, the generative AI platform developed by OpenAI. This specific campaign utilizes Google’s sponsored search results to direct unsuspecting users to a malicious "Custom GPT" hosted on the legitimate OpenAI domain, eventually tricking them into executing commands that install malware on their local systems. Unlike traditional phishing attempts that rely on look-alike domains or typosquatting, this campaign is particularly dangerous because it originates from the official ChatGPT website, effectively bypassing the initial skepticism many users have toward unfamiliar URLs.

The Mechanics of the Custom GPT Exploit

The lifecycle of this scam begins with a standard user behavior: searching for "ChatGPT" on a major search engine like Google. Because OpenAI’s platform is one of the most visited websites globally, the keyword "ChatGPT" is a high-value target for "malvertising"—a portmanteau of malicious advertising. Scammers purchase sponsored ad slots that appear at the very top of the search results page, often above the organic link to the authentic OpenAI homepage. These ads are designed to look identical to legitimate promotional links, complete with professional-looking descriptions and seemingly valid display URLs.

When a user clicks on one of these sponsored results, they are not taken to the standard ChatGPT interface. Instead, they are redirected to a specific "Custom GPT." Introduced by OpenAI in late 2023, Custom GPTs allow users to create specialized versions of the AI for specific tasks, such as coding assistance, creative writing, or data analysis. In this instance, threat actors have created a GPT designed to mimic a system-level error message.

Upon landing on the page, the user sees a message that appears to be an official "Service Availability Notice." The prompt informs the user that OpenAI is "currently experiencing limited availability on the primary domain" and offers two options to continue: upgrading to a "Plus" subscription or using a "backup domain." Because the user is physically on chatgpt.com and may even see their own profile logged in, the illusion of legitimacy is nearly perfect. The scam relies on the user’s trust in the primary domain to override any suspicion regarding the unusual "Plus 5.6" branding or the abrupt service notice.

From Deceptive Chat to Malware Execution

The critical phase of the attack occurs when the user clicks the provided "backup domain" link. This link redirects the user away from OpenAI’s ecosystem to a third-party site, frequently hosted on free services such as Google Sites. These external pages are designed to look like a Cloudflare "Verify You Are Human" security check—a common sight for internet users today. However, this is a "fake-out" verification screen.

This new ChatGPT scam tricks you into installing malware – how to spot the trap

Instead of the standard "Click here to verify" checkbox, the site presents a set of instructions. It claims that for security reasons, the user must manually verify their identity by performing a series of keyboard shortcuts and commands. The instructions typically direct the user to:

  1. Press Win + R to open the Windows Run dialog.
  2. Paste a specific string of code into the box.
  3. Press Enter to execute the command.

This string of code is a PowerShell command. PowerShell is a powerful task automation and configuration management framework from Microsoft, consisting of a command-line shell and associated scripting language. By tricking the user into manually pasting and running this command, the attackers bypass many automated security filters that would otherwise block a malicious file download. The command typically initiates a background process that reaches out to a remote server, downloads a malicious payload (such as an infostealer or a remote access trojan), and executes it with the user’s own permissions. This technique is often referred to by security professionals as "Self-Hacking" or "Pastejacking," as it relies entirely on the user’s cooperation to breach the system.

Chronology of the Discovery

The emergence of this specific campaign was documented over several days as multiple users and tech journalists reported identical experiences.

  • Initial Reports: Users on social media and technical forums began noting that Google searches for ChatGPT were leading to "System Availability" notices rather than the chat interface.
  • Verification: Journalists at ZDNET and other tech outlets attempted to replicate the results. While not every search triggered the malicious ad—indicating that the scammers may be using "cloaking" techniques to show the ad only to specific geographic regions or browser types—investigators successfully landed on the scam page through a standard Google search.
  • Technical Analysis: Security specialists identified that the malicious GPTs were named with versions like "Plus 5.6," a naming convention that does not exist in OpenAI’s official roadmap, which currently focuses on models like GPT-4o and o1-preview.
  • Platform Response: Following the public exposure of the campaign, Google confirmed that it had deactivated several advertiser accounts associated with the malicious ads. OpenAI has been made aware of the abuse of its Custom GPT feature to facilitate phishing, though the platform’s open nature makes it a continuous "cat-and-mouse" game for content moderators.

The Broader Context of Malvertising Trends

This incident is part of a broader, alarming trend in the cybersecurity world. According to data from various threat intelligence reports, malvertising increased by nearly 40% in 2023 and has continued to evolve in 2024. Threat actors have realized that compromising the supply chain of information—in this case, the search engine results—is often more effective than trying to break into a secure server.

Previous iterations of this scam have targeted software like WinRAR, VLC Media Player, and various cryptocurrency wallets. However, the integration of AI platforms adds a new layer of danger. Because ChatGPT is a relatively new tool for the general public, many users are not yet familiar with its standard operating procedures, making them more susceptible to claims of "limited availability" or "new version 5.6." Furthermore, the fact that the scam is hosted on the actual chatgpt.com domain represents a significant shift in phishing tactics. It exploits the "Domain Authority" of the target site itself, making it nearly impossible for basic URL-based security filters to flag the initial landing page as dangerous.

Statements and Official Reactions

In response to the discovery, a spokesperson for Google emphasized the company’s commitment to platform integrity, stating, "Malvertising has no place on Google. We’ve suspended several advertiser accounts to block this campaign and we continuously update our defenses to stop new threats." Despite these efforts, security experts warn that the automated nature of ad auctions allows bad actors to quickly spin up new accounts under different identities.

This new ChatGPT scam tricks you into installing malware – how to spot the trap

Roman Oliinyk, CEO and founder of PayCore Media Inc. and a specialist in network security, noted that the sophistication of the social engineering involved is what makes this attack successful. "A real Cloudflare check would never ask you to do anything on your keyboard," Oliinyk explained. "At most, it asks you to check a box or press a button. The moment a website asks you to open a terminal or run a command, it is 100% a malicious actor."

Analysis of Implications for Corporate and Personal Security

The implications of this scam are twofold. For individual users, the risk involves the theft of personal data, saved passwords, and financial information through infostealer malware. For corporate environments, this represents a significant "Shadow AI" risk. Employees looking to use AI to increase productivity may inadvertently introduce malware into a corporate network by following these "verification" steps.

This attack highlights a critical vulnerability in the "Custom GPT" ecosystem. While OpenAI intended for these tools to be a boon for productivity, they also provide a legitimate-looking stage for malicious scripts. If a threat actor can convince a user that the GPT they are talking to is a "system bot" or an "official support tool," the level of trust is significantly higher than a standard phishing email.

Recommendations for Prevention and Mitigation

To defend against these evolving threats, cybersecurity experts recommend several layers of protection:

  1. Ignore Sponsored Results: When searching for tools or software, skip the "Sponsored" section and look for the organic search results. Better yet, navigate directly to known URLs (e.g., chatgpt.com) by typing them into the address bar.
  2. Scrutinize "System" Messages: Legitimate web services rarely use a chatbot to announce domain-wide outages or "backup domains." Official status updates are typically found on dedicated status pages (e.g., status.openai.com).
  3. Never Run Unknown Commands: Under no circumstances should a user copy and paste code into a terminal, PowerShell, or the Windows Run box at the behest of a website. This is the digital equivalent of handing over the keys to one’s home.
  4. Use Ad-Blockers and DNS Filters: Utilizing reputable ad-blocking extensions can prevent many malvertising links from appearing in the first place. Additionally, DNS filtering services can block connections to known malicious domains used in the second stage of the attack.
  5. Enable PowerShell Restrictions: For corporate IT departments, implementing "Constrained Language Mode" for PowerShell or requiring script signing can prevent unauthorized commands from executing on company machines.

As AI continues to integrate into daily life, the methods used by cybercriminals will only become more creative. This latest campaign serves as a stark reminder that even on a trusted domain, the content provided by users—or in this case, "Custom GPTs"—requires a high degree of scrutiny. Vigilance and a basic understanding of how systems communicate with users remain the most effective defenses against the rising tide of AI-driven scams.

By