Fake ChatGPT Plus 5.6 Model on chatgpt.com Spreads a Trojan

Introduction

A sophisticated threat campaign has leveraged legitimate platform infrastructure to deceive users. Specifically, a fake ChatGPT Plus 5.6 model on chatgpt.com spreads a trojan to unsuspecting victims. Security researchers have uncovered coordinated efforts where malicious actors combined paid search advertisements, official hosting domains, and custom chatbot features to deliver remote access malware.

The campaign highlights evolving tactics among cybercriminals who increasingly abuse trusted domains and developer features to bypass traditional security filters. By hijacking the credibility of well-known platforms, attackers lower the defensive guard of everyday users and corporate workers alike.

What Changed

Attackers built a malicious Custom GPT titled ‘Plus 5.6’ and promoted it using paid Google advertisements. These ads directed traffic to chatgpt.com, a legitimate and trusted domain. Once users interacted with the Custom GPT, the model provided a uniform service notice claiming that ChatGPT was running with limited availability. It instructed users to either upgrade to Plus or continue on an alternative backup domain.

The backup domain link directed visitors to a Google Sites page designed to mimic a Cloudflare security verification check. This fraudulent page employed a technique known as ClickFix, telling visitors to copy a specific command and paste it directly into their computer’s Terminal or PowerShell interface. Executing this command triggered an eight-stage infection process that installed a remote access trojan on Windows PCs, hiding behind a signed Canon application and an audio file.

Context and Discovery

Security firm Huntress documented a campaign on September 28, counting at least 40 incidents tied to the malicious Google Sites page, with two victims demonstrably reaching the page through the Custom GPT. OpenAI removed the first rogue GPT by September 25 after receiving a report from Huntress. However, just two days later on September 27, Huntress identified a second Custom GPT sharing the exact same name.

A separate report published by security firm Island on October 1 tracked a similar threat campaign operating from late May to August 24. Island’s investigation uncovered approximately 850 paid-ad landings, 26 lookalike ChatGPT destinations, and 71 Google Ads campaign IDs. Island observed behavior consistent with the NetSupport RAT, a legitimate remote support tool frequently abused by criminal operators. Notably, neither Huntress nor Island officially links the two separate campaigns together.

Why It Matters

The exploitation of trusted domains represents a severe challenge for modern cybersecurity architecture. According to industry observations, attackers heavily value real and recognized domains because automated security filters readily let them through, and everyday users naturally trust them. When malicious activity occurs directly on a platform like chatgpt.com, standard indicators of compromise fail to trigger immediate alarms.

Furthermore, the campaign weaponizes human psychology. By mimicking standard infrastructure error notices and cloud security checks, the threat actors create a false sense of urgency and authority. Users accustomed to routine verification screens are easily manipulated into performing dangerous administrative actions.

Technical Explanation of the Attack

The infection vector relies heavily on social engineering and native operating system tools. The ClickFix technique bypasses traditional executable download blocks by convincing the user to manually execute code. When the victim pastes the copied command into PowerShell, the script executes an intricate multi-stage routine.

Over eight distinct stages, the payload extracts and executes malicious code while utilizing a legitimate, signed Canon application alongside a harmless audio file to mask its behavior. This technique, known as file payload masking or living-off-the-land execution, helps the malware evade local antivirus solutions and endpoint detection systems by hiding behind trusted software certificates.

Sector Impact and Business Implications

Businesses face growing risks as generative artificial intelligence tools become deeply integrated into daily workflows. Employees who rely on tools like ChatGPT for productivity tasks may encounter malicious Custom GPTs or sponsored lookalike ads during routine searches. If an employee’s machine is compromised by a remote access trojan, corporate networks, credentials, and proprietary data are exposed to unauthorized actors.

The incident places additional pressure on platform operators to monitor user-generated extensions and developer marketplaces aggressively. The speed at which threat actors spun up replacement GPTs after OpenAI’s initial takedown demonstrates the resilience and agility of modern cybercrime syndicates.

Who May Be Affected

Any individual or organization utilizing web-based AI tools via search engines is potentially exposed to sponsored malvertising campaigns. Windows PC users are specifically targeted by the PowerShell and ClickFix scripts associated with this particular incident. Corporate environments where employees have administrative execution rights on their workstations face heightened exposure to remote access trojans.

Limitations and Platform Changes

OpenAI is actively modifying its platform architecture to address security challenges related to extensibility features. The company announced plans to retire Custom GPTs entirely. The creation of new Custom GPTs is scheduled to end on October 26, and existing GPTs will be retired on December 11, with plans to replace them with alternative plugin architectures. Shared chats remain available according to official guidance, even as these developer tools are phased out.

What to Watch Next

Security analysts and enterprise IT teams must monitor how threat actors pivot their malvertising strategies as Custom GPTs are officially retired later in the year. Observers should also watch for evolving ClickFix distribution methods across other popular SaaS platforms and collaboration tools. As experts emphasize, no legitimate website, chatbot, support page, or verification tool has a valid reason to instruct a user to paste an unknown command into PowerShell or any terminal.