ChatGPT malware scam uses fake ads to install Windows malware
A new scam disguises itself as a ChatGPT page, tricks users into running a PowerShell command, and drops malware on Windows computers.
Over the past several days users searching for ChatGPT have encountered a fake site that pretends to be the official service and then tries to install malware on Windows computers. The scam begins with a paid Google ad that looks like a legitimate link to ChatGPT, but it actually points to a custom GPT that always returns a "Service Availability Notice" and a link to a malicious page. Clicking the link leads to a fake Cloudflare check that asks the user to paste a PowerShell command, which then installs malicious software.
How the scam works
According to ZDNET, the attack starts when a user types "ChatGPT" into Google and clicks a sponsored result that appears above the real search results. The ad leads to a custom GPT, a user‑generated version of ChatGPT, that displays the same limited‑availability message regardless of the query. The message includes a link labeled something like "Plus 5.6" that looks like an upgrade offer. When the link is followed, the user is taken to a free site hosted on Google Sites. That site shows a fake Cloudflare verification page and then instructs the visitor to copy and run a PowerShell command. Executing the command downloads and runs malware on the computer.
The article notes that not every sponsored result is malicious; the author was able to reach the real ChatGPT from a different ad. Google says it has deactivated several advertiser accounts linked to the campaign, but the threat could reappear.
Why the fake page looks authentic
The scam is convincing for a few reasons. First, the URL displayed in the browser is the genuine chatgpt.com domain, and the user may already be logged into their OpenAI account. Second, the custom GPT uses a model name that resembles official OpenAI naming conventions, so users unfamiliar with the naming scheme may not notice the discrepancy. Third, the fake Cloudflare page mimics the look of a real security check, but it asks the user to type a command, something a legitimate Cloudflare challenge would never do. As Roman Oliinyk of PayCore Media explains, “At most,” he said, “it asks you to check a box or press a button.”
Steps to protect yourself and your team
- Type the URL directly: Enter
chatgpt.comin the address bar instead of clicking search results. - Avoid sponsored links: Treat any paid ad in Google as potentially unsafe, especially when it promises access to a service you already use.
- Never run unknown commands: If a web page asks you to copy and paste code into PowerShell, Command Prompt, or any terminal, close the page immediately.
- Verify Cloudflare checks: Real Cloudflare challenges only require you to click a checkbox or press a button; they never request keyboard input.
- Keep software updated: Regularly apply Windows updates and enable built‑in security features such as Windows Defender and controlled folder access.
- Use multi‑factor authentication: Secure your OpenAI account and any other services you access from the same device.
- Report suspicious ads: Use Google’s ad feedback tools to flag malicious ads, helping to protect other users.
What to do if you think you ran the command
If a team member has already pasted the PowerShell command, take these actions immediately:
- Disconnect from the network to stop any further communication with the attacker.
- Run a full scan with Windows Defender or another reputable antivirus to identify and remove the malware.
- Change passwords for any accounts accessed from the compromised machine, especially the OpenAI account.
- Review admin access on any critical systems and revoke any unexpected privileges.
- Notify your IT or security provider so they can assess whether additional remediation is needed.
Staying vigilant about where you click and what you run on a computer can stop this kind of self‑inflicted attack before it harms your business. As the ZDNET report points out, Google is actively suspending advertiser accounts tied to the scam, but the safest approach is to avoid the ad altogether and use the direct domain.
For more guidance on using AI tools safely and automating routine tasks, visit our AI resources page.
Sources
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.