Fake ChatGPT Ads Are Tricking People Into Running Code
Sponsored search ads for fake ChatGPT tools are leading people to a fake verification page that installs a remote access trojan.
Updated 2026-10-02
A malicious version of ChatGPT has been promoted through paid Google search results, sending people to a fake site that tricks them into installing a remote access trojan. Security researchers at Huntress identified the campaign and found it had affected dozens of users. The attacker abused a genuine OpenAI feature, custom GPTs, which lets anyone build a version of ChatGPT with its own instructions and add-ons. OpenAI plans to retire custom GPTs entirely on 11 December, and has already removed at least one of the malicious ones.
The fake GPT, named 'Plus 5.6', pointed people to what it called a backup site, hosted on Google Sites. That page showed a fake Cloudflare 'check' and told visitors to run a PowerShell command to prove they were human. Anyone who copied and ran it started an infection chain: a malicious installer that launches a genuine, signed application alongside a doctored file that quietly loads the actual malware. This technique is known as ClickFix, and it works because the fake verification step looks routine and technical, not obviously suspicious.
The payload is a remote access trojan. Once running, it can give an attacker remote desktop access, turn on the camera and microphone, search files on the device, and download further malware. For persistence, it creates a Windows Registry entry and a scheduled task, both named 'Canon Configuration Reader', so it survives a restart. Huntress also found a newer version of the same campaign using a Stardock-signed application instead of a Canon one to hide the loader, though the malware itself stayed the same. Much of the infection runs in memory, which is part of why it can go unnoticed.
Huntress looked into at least 40 incidents connected to the malicious page, though only two were confirmed to have come through a fake custom GPT specifically. The wider point stands regardless of the exact route: a sponsored search result claiming to be an AI tool led people to a page that asked them to run code, and some did.
What this actually means for you
This is not a story about ChatGPT being hacked, and there is no sign that account passwords or payment details were involved. It's a story about how a paid ad and a fake verification screen can lead an ordinary, careful person to run one command they shouldn't. Nobody clicked their way into infection just by seeing the ad or visiting the page. Everything hinged on that one PowerShell command, and only devices where it was actually run are at risk.
What to do
- Treat sponsored search results for 'ChatGPT', 'ChatGPT Plus' or similar with suspicion. Go to openai.com directly rather than clicking an ad.
- Never copy and run a command from a webpage, especially one presented as a 'human verification' or 'Cloudflare check'. Real verification does not ask you to open PowerShell or Terminal.
- If you have run such a command, disconnect the device from the internet straight away, run a reputable anti-malware scan, and get professional help if you're not confident doing this yourself.
- Open Windows Task Scheduler and check your Registry Run keys for anything called 'Canon Configuration Reader'. Remove it if you find it and you don't recognise it.
- Be wary of any AI tool or chatbot that tries to send you to an external 'backup' site to keep using it. That redirection step is where this campaign does its damage.
- If you're unsure whether a link, download or message is genuine, check it before you act on it. Veystrix's free tools at /tools/url and /tools/scam can check a suspicious link or message without you having to open it yourself.
What this does not fix
A VPN does not stop you from running a malicious command, and it will not remove malware once it's on your device. It hides and encrypts your connection, which is useful for privacy, but it has no say over what happens after you double-click an installer or paste something into PowerShell. The actual defence here is pausing before you run anything a webpage asks you to run, no matter how official the page looks.
Check a suspicious message Free, and it needs no account.