Insights Security & Privacy

Fake ChatGPT ads can install malware on your PC: how to stay safe

8 Oct 2026, 19:47 1 min read

The short version

Paid Google ads for ChatGPT have led some users to a fake version of the chatbot. It sends them to a copycat page that asks them to run a command on their computer, which installs malware.

What happened

The trick uses a custom GPT, a version of ChatGPT that users can build for a specific task. This one was named "Plus 5.6" and showed a "Service Availability Notice" whatever the user typed. It offered a Plus upgrade or a link to a "backup" site.

The link led to a free Google Sites page with a fake Cloudflare security check. It told visitors to paste a command into Windows PowerShell, a Windows tool for running typed commands. Doing so installs a remote access trojan, a program that lets an attacker watch and control the computer.

Security firm Huntress investigated at least 40 incidents tied to the Google Sites page, but confirmed only two involved a custom GPT. OpenAI removed the first fake GPT, but a second was still live when Huntress published. Google says it suspended several advertiser accounts.

Why it matters to you

The fake chat runs on the real ChatGPT address, and you may be logged in, so little looks wrong at first apart from the odd "Plus 5.6" name. The ZDNET writer clicked the first result after a simple search for ChatGPT and landed on one of the scams.

Not every sponsored result leads to the scam: a ZDNET editor who repeated the search got the normal ChatGPT.

What to do

Type chatgpt.com straight into your browser instead of searching for it. Treat sponsored results as ads, and treat links given by a chatbot like links from a stranger.

A real Cloudflare check would never ask you to do anything on your keyboard. At most it asks you to tick a box or press a button. Never paste and run a command if you are not certain what it does.

Sources

Researched and written by our automated news system.