Security researchers and users have reported a fresh cyberattack campaign that impersonates OpenAI’s ChatGPT service to distribute malware. The scheme leverages paid search advertisements to lure victims into clicking deceptive links, ultimately compromising their computers.
The attack initiates when a user searches for “ChatGPT” on Google and selects a sponsored result. Although the URL appears legitimate and retains the official domain, the destination is actually a custom-built GPT application rather than the authentic service. This rogue interface is programmed to ignore user queries and consistently display a fabricated message titled “Service Availability Notice.” The prompt claims the primary platform is experiencing limited access and directs the user toward an upgrade option or a backup link.
The deception is reinforced by the fact that the custom GPT operates on the real ChatGPT domain and preserves the user’s existing login session, making it difficult to distinguish from the genuine site at first glance. The fraudulent bot is labeled “Plus 5.6,” a designation that may not raise alarms among users unfamiliar with OpenAI’s specific model naming conventions.
Once the victim follows the embedded link, they are redirected to a page hosted on Google Sites. This intermediate site mimics a Cloudflare security verification check and provides instructions to copy and execute a command within Windows PowerShell. Executing this command installs malicious software on the user’s machine.
Testing by ZDNET confirmed that clicking the top sponsored result led directly to the malicious custom GPT, which repeated the same availability error regardless of input. However, not all sponsored links in the search results appear to be compromised, as editorial staff members were occasionally redirected to the legitimate ChatGPT service.
Roman Oliinyk, founder of PayCore Media and a network security expert, emphasized that legitimate security checks do not require user interaction beyond simple verification boxes. He noted that a real Cloudflare validation would never ask a user to type or paste commands into a terminal. “At most,” Oliinyk explained, “it asks you to check a box or press a button.”
Experts advise users to bypass search engines entirely when accessing the service by typing ChatGPT.com directly into the browser address bar. Additionally, cybersecurity officials recommend exercising extreme caution with sponsored search results, which have a documented history of being weaponized to promote malware. Google has recently begun utilizing its Gemini AI system to detect and block malicious advertisements.
Oliinyk also suggested treating all links generated by chatbots with the same skepticism one would apply to links received from unknown individuals. While Google has confirmed it is investigating the incident, OpenAI has not yet issued a public statement regarding the exploitation of its platform for this malware distribution scheme.
How does OpenAI allow custom GPTs to hijack their main domain like this? Their moderation seems incredibly lax on security loopholes.
Just typed ChatGPT directly into the browser instead of clicking any search results. Lesson learned the hard way with a friend’s infected laptop.
Google needs to take more responsibility here. They are monetizing these scams through ad revenue. Why are these links still running?
This is terrifying. The fact that it uses the real ChatGPT domain makes it nearly impossible to spot without deep technical knowledge.
I cannot believe anyone would actually copy-paste a PowerShell command from a random webpage. People are so gullible.