Malicious custom GPT hosted on chatgpt.com, promoted in Google ads, leads users to a remote access trojan
Huntress says it has responded to at least 40 incidents linked to the campaign's Google Sites domain.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
Attackers are using OpenAI's custom GPT feature to spread malware, according to researchers at Huntress. A custom GPT named "Plus 5.6" appeared in sponsored Google Search results for people searching for "chatgpt." Because the page is hosted on the legitimate chatgpt.com domain, it looks trustworthy. When users try to use it, the GPT says the service is unavailable and sends them to a "Backup Domain" on Google Sites. That page imitates a Cloudflare CAPTCHA check and uses the ClickFix technique, telling visitors to copy a command into their terminal. Running the command starts an infection chain that ends with a remote access trojan. Huntress says its security operations center has responded to at least 40 incidents stemming from the Google Sites domain, and it confirmed that two of them came through a custom GPT. Huntress has previously seen deceptive ChatGPT conversations used for ClickFix lures, but it says using custom GPTs is new. BleepingComputer notes that OpenAI plans to retire custom GPTs on December 11. Until then, users should be wary of any chatbot page that tells them to paste commands into a terminal.