1 OCT 2026 — The security firm Huntress reported on 28 September that people who searched Google for "chatgpt" were shown a paid ad that landed on a real chatgpt.com page. The page was a Custom GPT built by attackers and named "Plus 5.6" to look like a new ChatGPT model. No matter what visitors typed, it sent them to a fake "backup domain" that installed a remote-access trojan.
OpenAI removed the first Custom GPT after Huntress reported it. Two days later Huntress found a second one from the same campaign, still live when the report was published.
How the lure worked
Custom GPTs are versions of ChatGPT that anyone can build and publish. They live on the real chatgpt.com domain, and the page shows the GPT's name at the top with its builder underneath. This one said it was by a "community builder", which is a clue for people who know what Custom GPTs are and easy to miss for those who do not.
The GPT was set up to give one reply to every message: a "service availability notice" saying ChatGPT had limited availability and offering a backup domain. That link led to a Google Sites page dressed as a Cloudflare security check, which told visitors to copy a command into their computer and run it.
That technique is known as ClickFix: instead of exploiting a software flaw, it persuades the victim to run the attacker's command themselves. The Huntress URLs carried Google Ads tracking parameters, which is how the researchers knew the visits came from a paid search result.
What was installed
The command pulled down an installer that dropped a digitally signed Canon application alongside tampered files. When the Canon application started, it loaded the attackers' code, a trick called DLL sideloading that lets malware run under a trusted name. The final payload is a remote-access trojan able to view the desktop, capture audio and camera, search files and run further software.
Each stage was hidden to slow down detection, including a loader tucked inside a .wav audio file. In one incident Microsoft Defender quarantined the installer only after it had run, and the persistence it had already set up kept the attack going, Huntress says.
How many people were hit
Huntress's security team responded to at least 40 incidents tied to the campaign's Google Sites page. It confirmed that two of those began with the Custom GPT. The rest reached the same page by other routes, so the fake GPT is one lure in a wider campaign rather than the whole of it.
That is the number Huntress's own team handled, not the total number of people who clicked.
Why the real domain matters
The usual advice is to check the web address before trusting a page. Here the address was correct. The lure sat on chatgpt.com, reached through a Google result, which is the path most people use to find ChatGPT. Huntress says attackers have also abused Claude Artifacts and shared ChatGPT conversations the same way.
The simplest defence is at the last step. "No legitimate website will ever ask you to copy and paste a command to prove you're human," Huntress said, as Infosecurity Magazine reports. A "backup domain" offered by a chatbot is a second warning sign.
What platforms can do
Taking down one Custom GPT did not end the campaign; a replacement appeared two days later. The paid search ad is the other link in the chain, and we found no statement from Google on it, or from OpenAI on the campaign.
BleepingComputer reports that OpenAI plans to retire Custom GPTs on 11 December, which would close this particular route. The ClickFix page and the paid ads would still work with any other lure.
RECATOOLS is written with the assistance of Claude, made by Anthropic, one of the AI platforms Huntress says has been abused in similar ways. Readers should weigh that interest.