
What happened
Huntress found attackers naming a Custom GPT "Plus 5.6" on the real chatgpt.com, sometimes reached via sponsored Google results, then steering users to a Google Sites page and a PowerShell command. It confirmed at least 40 incidents tied to that Google Sites domain, two via Custom GPT.
Why it matters
Because the page opened inside the real chatgpt.com domain, users saw the ordinary ChatGPT screen and trusted it, which let attackers misuse that trust to get victims to run the command themselves, Huntress said.
What to watch
The first Custom GPT Huntress reported was removed by September 25, but a different one tied to the same campaign appeared by September 27, so the test is whether OpenAI's takedowns outpace replacements ahead of Custom GPT retirement on December 11.
WHO IT HITSEmployees who reach ChatGPT through search ads and follow its on-screen prompts are the ones this lands on, since the abuse works by making a legitimate-looking ChatGPT page the entry point. IT and security teams overseeing endpoint protection may need to treat "run this PowerShell command" prompts as a malware risk on staff machines.
Summaries like this, in your inbox every morning.
The attack's entry point is not a fake website but a feature that lives inside ChatGPT itself. Custom GPTs run under the legitimate chatgpt.com domain, so from the user's side the page looks like an ordinary ChatGPT screen. Huntress notes the page even carried a "community builder" label marking it as third-party, but says users unfamiliar with how Custom GPTs work could still mistake it for the standard interface. Attackers leaned on that trust, naming the GPT "Plus 5.6" to resemble a genuine model and turning a search ad into the front door.
From there the chain left OpenAI's domain for Google Sites, where a Cloudflare-style CAPTCHA appeared and the supposed verification step was pasting a PowerShell command into Windows, a pattern Huntress calls ClickFix. Huntress reports this was more elaborate than typical ClickFix attacks, with an eight-stage infection path, and says it confirmed at least 40 incidents linked to the same Google Sites domain, two of them arriving through Custom GPT. The first Custom GPT it reported to OpenAI was removed by September 25, but another tied to the same campaign surfaced on September 27, and Huntress has previously seen shared ChatGPT conversations and shared Claude content used the same way.
What the outcome hinges on is speed: whether reported Custom GPTs are taken down before replacements appear, and whether search ads remain a viable way in. OpenAI said in September 2026 that Custom GPTs will be discontinued on December 11, 2026, which may narrow this particular route — though the broader approach of borrowing trust from well-known services to get victims to run commands themselves would not automatically disappear with it.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Carvana and CarMax are jockeying as agentic AI tools look to fix the worst parts of car buying, with AI shoppi…

Google DeepMind launched Gemini 4 Argon for coding, enterprise knowledge work and cyber defense, claiming firs…

Bloomberg reports Amazon's delivery smart glasses shoot still images at intervals during walks, possibly thous…

After forcing Hermes Agent's backend to Vulkan with the command "hermes config set local_runtime.backend vulka…

The Information reports Google's "AI Contribution Pilot Program" pays about 100 digital publishers, including…

Nathan Langley (ninjahawk) of the University of North Carolina released livenerf, a benchmark built on Britain…
