Cybersecurity Alert: A Fake ChatGPT “Plus 5.6” Installed on the Official Site Traps Windows Users
An Invisible Threat at the Heart of the ChatGPT Official Website
Going to chatgpt.com, the official OpenAI domain, should be a guarantee of security. However, a recent cyberattack campaign proves the opposite. Security researchers at Huntress have discovered a sneaky method that allows hackers to install a Remote Access Trojan (RAT) on Windows computers by bypassing a legitimate feature of ChatGPT: Custom GPTs.
This article will also interest you: Instagram Security Breach: How Meta AI Facilitated the Hacking of 20,000 Accounts
The scheme relies on a malicious custom GPT dubbed “Plus 5.6,” a name that intentionally mimics OpenAI model nomenclature to deceive users. Hosted directly on the chatgpt.com domain, this fake model does not present, at first glance, any worrying distinctive sign, except for a discreet “community builder” mention which escapes most Internet users.
The Modus Operandi: Google Ads and Fake Backup Domains
To attract their victims, the attackers used sponsored Google Ads advertisements. By simply searching for “ChatGPT” on Google, users clicked on the first sponsored link, which redirected them to the real domain chatgpt.com, but to the fake GPT “Plus 5.6”. Since the address displayed in the browser is authentic, the victim has no reason to be suspicious.
Once on this false model, whatever question is asked, the response is the same: a message claiming that the service is experiencing “heavy traffic” and inviting the user to continue on a “backup domain”. This link leads to a page hosted on Google Sites, disguised as Cloudflare's CAPTCHA verification.
The ClickFix Technique: When the Victim Runs the Virus Themselves
The “verification” page asks the user to copy and paste a command into the Windows “Run” window (Win+R). This command launches PowerShell, Windows' scripting tool, which downloads and installs a remote access Trojan in several steps.
This attack method has a name: ClickFix. According to Microsoft's Digital Defense 2025 report, it represented 47% of initial compromises detected between July 2024 and June 2025, ahead of classic phishing (35%). ClickFix exploits a common reflex: the user thinks he is solving a trivial technical problem, when he himself is compromising his machine.
Stealth and Persistent Malware
To evade antiviruses, the malware uses a DLL sideloading technique. It hides behind a real application signed by Canon (COTFileReadApp.exe) and a .wav audio file, part of which contains encrypted code. Once installed, the RAT allows hackers to:
- View the victim's screen
- Record webcam and microphone
- Search files
- Download other malware
Huntress has documented at least 40 incidents linked to this campaign. OpenAI removed the first GPT "Plus 5.6" on September 25 after Huntress's report. Two days later, a new GPT of the same name was already online, and the Canon application had been replaced by software from Stardock, with the same Trojan horse at the end.
A Second Campaign Confirmed by Island
On October 1, the company Island, publisher of a secure browser for businesses, published a second report describing a very similar campaign active from May to August 2026. Their researchers counted:
- ~850 arrivals via paid advertisements
- 26 fake ChatGPT destinations
- 71 distinct Google Ads campaigns
The message of the fake GPTs did not change: so-called “high traffic” and “emergency area”. Neither Island nor Huntress makes a formal connection between the two campaigns, but the similarities are striking.
The Future of Customized GPTs and the Persistence of Risk
OpenAI announced the retirement of custom GPTs for December 11, 2026, replaced by Plugins. This move could reduce this specific attack vector. However, ChatGPT's shared conversations — also used as bait in Island's campaign — will continue to work and could be exploited in the same way.
How to Protect Yourself: The Golden Rules
Faced with this threat, a few simple reflexes can help you protect yourself:
- Never click on sponsored ads in search results. Type chatgpt.com directly into the address bar or use a favorite.
- No legitimate site will ever ask you to copy and paste a command into the “Run” window (Win+R) or into a terminal to function. If a page asks you to do so, close the tab immediately.
- ChatGPT never links to a “fallback domain”. For the actual status of OpenAI services, visit status.openai.com.
- If you think you executed the malicious command:
- Disconnect the PC from the Internet immediately.
- Run a full virus scan.
- Change your important passwords from another device (phone, other computer).
Conclusion: A Lesson in Cybersecurity
This campaign illustrates a worrying trend: hackers no longer need to create crude fraudulent sites. They exploit legitimate features of trusted services and use paid advertising to make their lures appear legitimate. Vigilance remains the best defense. By adopting good habits — don't click on ads, go directly to official sites and never execute unknown orders — you considerably reduce the risk of falling into this type of trap.