Fake ChatGPT malware: how the Plus 5.6 GPT trap works
Fake ChatGPT malware hid behind a Plus 5.6 GPT on the real chatgpt.com, pushed by Google ads. How the ClickFix trap works and how to check your PC.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

"ChatGPT Plus 5.6" is not a new OpenAI model. It's a Custom GPT, a user-built chatbot hosted on the real chatgpt.com, that attackers used as the front door for fake ChatGPT malware and promoted with Google ads to people searching for "chatgpt". Every reply sent visitors to a fake Cloudflare check that asked them to paste a command into Windows, and that command installed a remote access trojan (RAT), malware that lets someone else control your PC. Security firm Huntress described the campaign on September 28, 2026, and counted at least 40 incidents.
Key takeaways
- The lure: a sponsored Google result for "chatgpt" led to a Custom GPT called "Plus 5.6" on chatgpt.com. Whatever you typed, it claimed ChatGPT was down and offered a "backup domain".
- The trap: that backup page, hosted on Google Sites, imitated a Cloudflare human check and told visitors to copy and paste a command. Huntress says running it installed a RAT that can watch the screen, record the camera and microphone, and read data from 17 browsers.
- The scale: Huntress tied at least 40 incidents to the same Google Sites page and confirmed 2 that started at the Custom GPT. Separately, Island counted about 850 paid-ad landings across 71 Google Ads campaign IDs from late May to August 24.
- The takedowns: OpenAI removed the first GPT by September 25 after Huntress reported it; Huntress found a new one tied to the campaign on September 27. As of October 2, neither OpenAI nor Google has commented publicly that we could find.
- The rule: no real website, CAPTCHA or "fix" needs you to paste a command into Windows. If a page asks, close it.
How the fake ChatGPT malware trap works
Huntress's write-up, by researchers Mark O'Halloran and Jonathan Semon, traces the chain step by step. It starts with a sponsored Google result for the search "chatgpt". The ad opens a Custom GPT titled "Plus 5.6", a name chosen to look like an upgraded ChatGPT model or plan. Huntress says any message you send it gets the same answer: a "Service Availability Notice" claiming the main ChatGPT domain is having problems, with a link to a backup.
That link goes to a page on Google Sites dressed up as a Cloudflare CAPTCHA. Instead of asking you to tick a box, it gives you a command to copy and paste and run. This is ClickFix, a trick Microsoft describes as getting people to paste commands into the Windows Run dialog, Windows Terminal or PowerShell, often framed as a human check or a quick fix.
Huntress says the command quietly downloads and installs a Windows installer package. That package drops a legitimately signed program, a Canon utility, or a Stardock one in later variants, next to a malicious file the program loads. The result is a full-featured RAT. According to Huntress, it can run remote desktop sessions, capture the camera, microphone and system audio, pull data from 17 browsers, search your files and install more malware. It hides its traffic to the attackers' servers inside DNS-over-HTTPS, the encrypted lookups that look like ordinary browsing.
Why the real chatgpt.com address made it convincing
Most phishing advice says to check the address bar. Here, the address bar was right. Custom GPTs live on chatgpt.com, under addresses that start with chatgpt.com/g/, and ChatGPT users can publish their own. A visitor saw the real domain, the real ChatGPT interface and a plausible outage message, so the first warning sign only appeared one click later, on a page that wasn't chatgpt.com at all.
The second layer of borrowed trust was Google itself. The ad sat above the normal results, and the fake check was hosted on Google Sites, not on an obviously strange domain. Neither platform was hacked; the attackers used both as stepping stones, borrowing the trust people place in them.
What's new since September 28
Three things have moved since the first coverage.
- The GPT came back. Huntress reported the first Custom GPT to OpenAI, which took it down by September 25. On September 27, Huntress found a new Custom GPT linked to the same campaign, and it was still live when Huntress published. Help Net Security reported on September 29 that the second GPT was still online but no longer pointed to the ClickFix page.
- The ads ran for months. In research published October 1, Island researchers Shachar Gritzman and Naveh Talmon Chvaicer tracked a sponsored-search delivery cluster from late May to August 24, 2026: about 850 paid-ad landings, 26 lookalike ChatGPT destinations and 71 Google Ads campaign IDs. One of the destinations they list is a Custom GPT address ending in "plus-5-6". In their cases, visitors were told to press Win+R and paste the command into the Run dialog.
- The payload may vary. Huntress doesn't name the RAT family. Island says the loader it saw behaved in a way "consistent with NetSupport RAT delivery"; NetSupport is a remote control tool long abused by criminals. Island makes no claim about who runs the operation. So treat the malware as whatever the attackers chose to deliver that week.
What OpenAI and Google have said
As of October 2, 2026, we found no public statement from OpenAI or Google about this campaign. The only OpenAI action on record is the removal Huntress reported. Neither Huntress, Island nor the coverage we read says whether Google has pulled the ads or suspended the advertisers.
One change is coming anyway. OpenAI plans to retire Custom GPTs on December 11, 2026, in favor of plugins, Virtualization Review reports. That would close this particular door, though not the wider trick: Island notes that Huntress had earlier documented searches leading to attacker-written ChatGPT and Grok conversations that told people to run commands.
How to tell if you ran the command
If you clicked a "chatgpt" ad, met a ChatGPT outage notice and then pasted something into Windows, assume the PC is compromised. Huntress's post is written for security teams, and these are the traces it lists:
- A scheduled task or startup entry named "Canon Configuration Reader". Huntress says the malware sets both, and each restores the other if you delete one. Check Task Scheduler and the Startup apps list in Settings.
- An unexpected program folder under
%LOCALAPPDATA%\Programs\holding a Canon file calledCOTFileReadApp.exeor a Stardock file calledDeElevate64.exe, with an unsigned DLL beside it. You can paste that path into File Explorer's address bar to look. - Your Run dialog history. Microsoft's ClickFix analysis points defenders to the RunMRU registry key, which records what was typed or pasted into Win+R.
Huntress doesn't publish a cleanup checklist for home users. The standard response for a remote access trojan is to disconnect the PC from the internet, then, from a different device, change the passwords saved in your browsers, starting with email and banking, sign out of other sessions and turn on two-factor authentication. Because this RAT re-creates itself, a full Windows reset is the safest fix. On a work computer, call your IT or security team before touching anything.
The one rule that stops ClickFix
No legitimate website, CAPTCHA or support page needs you to paste a command into the Run dialog, Terminal or PowerShell. Real Cloudflare checks run on their own or ask for a click at most. If a page tells you to press Win+R, or anything like it, close the tab. That one habit beats this campaign and every ClickFix variant, including the Mac versions we covered in our look at whether Meta Muse is safe.
Two more habits help. Type chatgpt.com yourself or use the app instead of clicking a search ad. And remember that OpenAI's models are picked from the model menu inside ChatGPT, not from a GPT with a model-like name.
Bottom line
This fake ChatGPT malware campaign, fronted by the "ChatGPT Plus 5.6" GPT, used a real domain, a real Google ad and a real-looking Cloudflare page to get people to run malware themselves. The fix is simple: never paste a command a website gives you. If you already did, treat the PC as compromised, check for "Canon Configuration Reader", and reset your passwords from another device. Watch for statements from OpenAI and Google on how the GPT and the ads got through, and for more security news in our software coverage.
FAQ
Is ChatGPT Plus 5.6 a real model?
No. ChatGPT Plus is a subscription plan, and "Plus 5.6" was the title of an attacker-made Custom GPT, according to Huntress. OpenAI's models appear in the model picker inside ChatGPT, not as a GPT you reach from an ad.
Is chatgpt.com safe to use?
ChatGPT itself wasn't hacked. The attackers published a Custom GPT on it, the way any user can. Using chatgpt.com directly is fine; the danger was the GPT's link to an outside page and the command that page asked you to run.
What is a ClickFix attack?
ClickFix is a social engineering trick that shows a fake error or human check and asks you to paste a command into Windows or macOS to "fix" it. Microsoft says it can slip past automated defenses because you run the command yourself.
Does this campaign affect Macs?
The chain Huntress documented targets Windows, using PowerShell and a Windows installer. ClickFix itself also targets Macs through Terminal, and the same rule applies there: never paste a command a website gives you.