AIToday
Large Language ModelsAI Safety & AlignmentGIGAZINE AIPublished: Oct 1, 2026, 16:00 JST

Huntress: fake Custom GPT "Plus 5.6" on chatgpt.com spread malware

Huntress: fake Custom GPT "Plus 5.6" on chatgpt.com spread malware

3 Key Points

  1. What happened

    Huntress found attackers naming a Custom GPT "Plus 5.6" on the real chatgpt.com, sometimes reached via sponsored Google results, then steering users to a Google Sites page and a PowerShell command. It confirmed at least 40 incidents tied to that Google Sites domain, two via Custom GPT.

  2. Why it matters

    Because the page opened inside the real chatgpt.com domain, users saw the ordinary ChatGPT screen and trusted it, which let attackers misuse that trust to get victims to run the command themselves, Huntress said.

  3. What to watch

    The first Custom GPT Huntress reported was removed by September 25, but a different one tied to the same campaign appeared by September 27, so the test is whether OpenAI's takedowns outpace replacements ahead of Custom GPT retirement on December 11.

WHO IT HITSEmployees who reach ChatGPT through search ads and follow its on-screen prompts are the ones this lands on, since the abuse works by making a legitimate-looking ChatGPT page the entry point. IT and security teams overseeing endpoint protection may need to treat "run this PowerShell command" prompts as a malware risk on staff machines.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The attack's entry point is not a fake website but a feature that lives inside ChatGPT itself. Custom GPTs run under the legitimate chatgpt.com domain, so from the user's side the page looks like an ordinary ChatGPT screen. Huntress notes the page even carried a "community builder" label marking it as third-party, but says users unfamiliar with how Custom GPTs work could still mistake it for the standard interface. Attackers leaned on that trust, naming the GPT "Plus 5.6" to resemble a genuine model and turning a search ad into the front door.

From there the chain left OpenAI's domain for Google Sites, where a Cloudflare-style CAPTCHA appeared and the supposed verification step was pasting a PowerShell command into Windows, a pattern Huntress calls ClickFix. Huntress reports this was more elaborate than typical ClickFix attacks, with an eight-stage infection path, and says it confirmed at least 40 incidents linked to the same Google Sites domain, two of them arriving through Custom GPT. The first Custom GPT it reported to OpenAI was removed by September 25, but another tied to the same campaign surfaced on September 27, and Huntress has previously seen shared ChatGPT conversations and shared Claude content used the same way.

What the outcome hinges on is speed: whether reported Custom GPTs are taken down before replacements appear, and whether search ads remain a viable way in. OpenAI said in September 2026 that Custom GPTs will be discontinued on December 11, 2026, which may narrow this particular route — though the broader approach of borrowing trust from well-known services to get victims to run commands themselves would not automatically disappear with it.

FAQ
How did users end up on the attacker's Custom GPT?
In some cases Huntress confirmed, users searched "chatgpt" on Google and reached the attacker's Custom GPT through a sponsored result. The link itself pointed to the legitimate chatgpt.com domain.
What happened after users typed into "Plus 5.6"?
It showed a message saying use was restricted on the main domain and told them to upgrade to ChatGPT Plus or use a "backup domain", which led to a Google Sites page. There, a CAPTCHA-like screen asked them to paste and run a specified PowerShell command on Windows.
What was the malware able to do once it ran?
A remote-access trojan, or RAT, was executed. According to Huntress, it could inspect antivirus status, Microsoft Defender state, network settings, installed software and hardware, and download and run additional files.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleWhite House AI accord called 'morally binding'