Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Fake ChatGPT Model on Official Site Delivers Remote Access Trojan

Дата публикации: 02-10-2026 23:02:15

Attackers created a "Plus 5.6" Custom GPT on the real chatgpt.com domain, promoted it via Google ads, and tricked users into running commands that installed a remote access trojan. The scheme used ClickFix tactics and persisted even after OpenAI removals. Security teams now face new challenges from trusted AI platforms turned attack vectors.

Основное содержимое страницы с новостью.

Users searching for ChatGPT on Google now face a new risk. Click the top sponsored result. Land on the real chatgpt.com domain. Type a prompt into what looks like an official model. The trap springs.

Security researchers at Digital Trends detailed the scheme this week. Attackers created a Custom GPT named “Plus 5.6.” The name mimics OpenAI’s branding. Paid Google ads pushed it high in search results for “ChatGPT.”

Everything appears legitimate. The URL shows chatgpt.com. No typos. No suspicious redirects at first. But the conversation follows a script. No matter the input, “Plus 5.6” claims the main service faces availability limits. It offers a backup domain instead.

That link leads to a Google Sites page. It displays a fake Cloudflare CAPTCHA. Instructions tell visitors to copy a specific command and paste it into Windows Run. This is the ClickFix technique. Victims execute the malicious payload themselves. No exploit needed. Just social engineering that exploits trust in the familiar.

The command launches PowerShell. It kicks off an eight-stage process. The end result installs a remote access trojan called “@input.” Attackers gain the ability to view the screen in real time. They control the camera and microphone. They search files at will. Additional malware drops become simple.

But. The infection hides cleverly. It uses signed legitimate binaries. One version employed a Canon application and an audio file. Another swapped in Stardock and Microsoft NuGet components. Detection becomes harder. The malware establishes persistence through registry Run keys and scheduled tasks named after legitimate software.

The Rapid Replacement Cycle

Huntress researchers spotted the campaign. They tracked at least 40 related incidents. Their report landed September 28. OpenAI removed the original malicious Custom GPT by September 25. Yet a near-identical replacement appeared two days later. Same name. Same behavior. Different internal ID.

This whack-a-mole pattern reveals the attackers’ resilience. They prepared backups. They monitored for takedowns. And they moved fast. The technique marks one of the first documented abuses of Custom GPTs for direct malware delivery. OpenAI plans to retire the Custom GPT feature entirely on December 11. That deadline now carries new weight.

A separate probe from Island uncovered a larger earlier operation. It ran from late May through August. The firm counted roughly 850 paid ad landings. Twenty-six lookalike ChatGPT destinations. Seventy-one distinct Google Ads campaign IDs. The scale suggests professional operators. Not hobbyists.

Earlier campaigns followed similar patterns. Push Security documented shared ChatGPT links hosting fake outage pages in May. Those led to impersonation download sites pushing infostealers on Windows and macOS. The tactics evolve. The platforms stay the same. Trust in OpenAI’s domain becomes the constant vulnerability.

Industry watchers note the broader shift. Threat actors treat AI platforms as attack surfaces. They host malicious instructions on legitimate domains. They poison search results. They combine paid ads with social engineering. The result bypasses many traditional defenses. Browser warnings don’t trigger. URL scanners see chatgpt.com.

OpenAI has not issued a detailed public statement on this specific incident. The company removed the GPTs after notification. Yet the speed of replacement shows limits in proactive moderation. Custom GPTs allow anyone to build and publish specialized bots. Vetting appears light. The feature’s upcoming retirement suggests OpenAI recognizes the problem.

Defenders recommend strict habits. Never run commands from unexpected sources. Verify downloads only from official OpenAI pages or app stores. Ignore “backup” or “alternative” links during outages. Use endpoint detection that monitors PowerShell and registry changes. Even then, sophisticated hiding techniques challenge detection.

The campaign highlights a deeper issue. As AI tools integrate into daily workflows, they become vectors. Users treat ChatGPT conversations as authoritative. They follow instructions without question. Attackers exploit that confidence. The fake model didn’t need to be sophisticated. It just needed to sound official and create urgency.

Island’s findings on the earlier wave add context. Hundreds of ads over months. Consistent messaging. Coordinated infrastructure. This wasn’t a one-off test. It was a sustained effort. The September incidents represent a new iteration using Custom GPTs instead of shared conversations. Evolution in action.

Security firms continue tracking related domains and payloads. The RAT’s capabilities extend beyond initial access. Screen viewing enables credential theft in real time. Microphone and camera access supports espionage. File exfiltration targets sensitive documents. The potential damage scales with the victim’s role.

Enterprise security teams now review policies around AI tool usage. Some block Custom GPTs outright. Others monitor for anomalous PowerShell execution following browser activity. The incident serves as a reminder. The address bar says chatgpt.com. That no longer guarantees safety.

Researchers expect more attempts. As OpenAI shuts one door, operators test others. Claude Artifacts. Grok shares. Shared conversations across platforms. The pattern repeats. Trust becomes the weakest link. And attackers keep finding new ways to abuse it.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures07.9930-09-2026
2Cerchi ChatGPT su Google? L’annuncio sbagliato può installarti un malware019.1303-10-2026
317,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360012.5624-09-2026
4Неизвестная модель ИИ атаковала правительственные сайты Канады07.701-10-2026
5Rogue AI bots have hacked into governments, universities and public agencies around the world, tech giant OpenAI admits07.1926-09-2026
6ChatGPT атаковал правительственные сайты США, Канады и Австралии012.2102-10-2026
7ChatGPT атаковал правительственные сайты США, Канады и Австралии012.2102-10-2026
8暴走AIエージェントが世界の政府・大学・公的機関に不正アクセス!? 米証券取引委員会や国勢調査局も被害、ユーザー画像の第三者流出53件01030-09-2026
9OpenAI informiert „dutzende“ Institutionen über unbefugte KI-Interaktionen021.5426-09-2026
103 guys hacked OpenAI using a rival Anthropic model. Here's what to know.011.7222-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 10.7. Источник: www.webpronews.com.