Cyber Threat Intel 5 min read

A Google Ad for ChatGPT Led to a Real chatgpt.com Page That Installed a Trojan

Attackers published a Custom GPT called "Plus 5.6" that sent every visitor to a fake backup site. OpenAI took it down; a replacement appeared two days later, Huntress reports.

Priya Nair
Data, AI Governance & Policy Analyst
Published 1 Oct 2026, 7:09 AM (SGT)
Share:
A phone on a stand showing the ChatGPT app's opening screen A phone on a stand showing the ChatGPT app's opening screen Photo by Tim Witzdam on Pexels
Advertisement

1 OCT 2026 — The security firm Huntress reported on 28 September that people who searched Google for "chatgpt" were shown a paid ad that landed on a real chatgpt.com page. The page was a Custom GPT built by attackers and named "Plus 5.6" to look like a new ChatGPT model. No matter what visitors typed, it sent them to a fake "backup domain" that installed a remote-access trojan.

OpenAI removed the first Custom GPT after Huntress reported it. Two days later Huntress found a second one from the same campaign, still live when the report was published.

How the lure worked

Custom GPTs are versions of ChatGPT that anyone can build and publish. They live on the real chatgpt.com domain, and the page shows the GPT's name at the top with its builder underneath. This one said it was by a "community builder", which is a clue for people who know what Custom GPTs are and easy to miss for those who do not.

The GPT was set up to give one reply to every message: a "service availability notice" saying ChatGPT had limited availability and offering a backup domain. That link led to a Google Sites page dressed as a Cloudflare security check, which told visitors to copy a command into their computer and run it.

That technique is known as ClickFix: instead of exploiting a software flaw, it persuades the victim to run the attacker's command themselves. The Huntress URLs carried Google Ads tracking parameters, which is how the researchers knew the visits came from a paid search result.

40+Incidents Huntress handled linked to the campaign's Google Sites page
2Of those confirmed to have come through a Custom GPT
25 SeptFirst Custom GPT taken down by OpenAI
27 SeptSecond Custom GPT from the same campaign found, still live

What was installed

The command pulled down an installer that dropped a digitally signed Canon application alongside tampered files. When the Canon application started, it loaded the attackers' code, a trick called DLL sideloading that lets malware run under a trusted name. The final payload is a remote-access trojan able to view the desktop, capture audio and camera, search files and run further software.

Each stage was hidden to slow down detection, including a loader tucked inside a .wav audio file. In one incident Microsoft Defender quarantined the installer only after it had run, and the persistence it had already set up kept the attack going, Huntress says.

How many people were hit

Huntress's security team responded to at least 40 incidents tied to the campaign's Google Sites page. It confirmed that two of those began with the Custom GPT. The rest reached the same page by other routes, so the fake GPT is one lure in a wider campaign rather than the whole of it.

That is the number Huntress's own team handled, not the total number of people who clicked.

Why the real domain matters

The usual advice is to check the web address before trusting a page. Here the address was correct. The lure sat on chatgpt.com, reached through a Google result, which is the path most people use to find ChatGPT. Huntress says attackers have also abused Claude Artifacts and shared ChatGPT conversations the same way.

Advertisement

The simplest defence is at the last step. "No legitimate website will ever ask you to copy and paste a command to prove you're human," Huntress said, as Infosecurity Magazine reports. A "backup domain" offered by a chatbot is a second warning sign.

What platforms can do

Taking down one Custom GPT did not end the campaign; a replacement appeared two days later. The paid search ad is the other link in the chain, and we found no statement from Google on it, or from OpenAI on the campaign.

BleepingComputer reports that OpenAI plans to retire Custom GPTs on 11 December, which would close this particular route. The ClickFix page and the paid ads would still work with any other lure.

RECATOOLS is written with the assistance of Claude, made by Anthropic, one of the AI platforms Huntress says has been abused in similar ways. Readers should weigh that interest.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement