fake-ChatGPT-from-ads

A "ChatGPT" that you land on via a Google ad may be fake: it sends you to a "redirect domain" where you end up running a command yourself that installs malware on your device.

Researchers at Huntress have documented a campaign that buys ads for the search term “chatgpt.” The sponsored link leads to a fake GPT called “Plus 5.6,” which displays an availability notice and asks you to switch to a “backup domain.” On that page, a fake Cloudflare verification appears—a method known as ClickFix—which tricks you into pasting and running a PowerShell command yourself.

The command installs a remote control program. Once launched, it takes screenshots, activates the camera and microphone, extracts saved passwords from 17 browsers, and gives the attacker control over the computer. So far, at least 40 people have been infected.

For a small business, the risk is very real: an employee searches for “ChatGPT” on Google, clicks on the first result without realizing it’s an ad, and, a few clicks later, runs the command that opens the backdoor without even realizing it. Antivirus software rarely blocks a command that the user runs manually.

Here's what you need to do, specifically:

  • Open the AI tools by typing in the official address (chatgpt.com) yourself, not from a sponsored result.
  • Tell your team this rule: no webpage or chat should ever ask you to open PowerShell or press Win+R and paste a command. If it does, close it.
  • If someone has already run such a command: shut down the computer, change your passwords on other devices, and check your recent logins.

A "fallback domain" for a service that has never gone down is a clear sign that you're not talking to the real service. Real services don't redirect you to another domain or ask you to run commands.

Sources:

This article was generated with AI assistance.

Request a quote

← All news