Fake ChatGPT GPT 'Plus 5.6' Spreads RAT via Google Sites
Huntress found a fake Custom GPT on ChatGPT.com that tricked users into installing a remote-access trojan via a Google Sites page posing as a Cloudflare check.
Security researchers at Huntress have uncovered a malware campaign that used a fake Custom GPT called 'Plus 5.6' on the real ChatGPT website to trick users into installing a remote-access trojan (RAT).
The fake GPT told users that ChatGPT was experiencing availability problems and offered a backup domain. That domain led to a Google Sites page posing as a Cloudflare security check, which instructed users to copy and paste a command into Windows. Running the command installed a RAT capable of viewing the screen, searching files, using the webcam and microphone, capturing system audio, and installing more malware.
Huntress investigated at least 40 incidents tied to the Google Sites domain and confirmed two infections from the malicious Custom GPT. OpenAI removed one GPT on September 25, and researchers found another linked to the same campaign two days later.
The campaign highlights how attackers can abuse trusted platforms like ChatGPT and Google Sites to deliver malware. Earlier this year, fake stores appeared in ChatGPT shopping recommendations, exposing shoppers to potential fraud. Researchers have also spotted Android malware using Gemini to change its behavior while running.
Quick answers
What is the fake Custom GPT called?
The fake Custom GPT is called 'Plus 5.6' and was hosted on the real ChatGPT website.
How does the malware spread?
It tells users ChatGPT has availability problems and offers a backup domain that leads to a Google Sites page posing as a Cloudflare security check, which instructs users to paste a command into Windows.
What can the installed trojan do?
The remote-access trojan can view the screen, search files, use the webcam and microphone, capture system audio, and install more malware.