How-to ·

ChatGPT Malware Scam: How to Spot and Avoid the Trap

You can avoid the new ChatGPT malware scam by ignoring sponsored search ads, navigating directly to the official domain, and never running PowerShell commands prompted by websites.

In short
  • Malicious sponsored Google ads lead to fake ChatGPT interfaces.
  • The scam uses custom GPTs to mimic the official platform.
  • Fake Cloudflare checks prompt users to run malware commands.
  • Always type the official ChatGPT web address directly.
In this guide
  1. What is the ChatGPT Google ad scam?
  2. How to spot the fake ChatGPT warning
  3. How to avoid the ChatGPT malware trap
  4. How tech platforms are addressing the ChatGPT malware threat
  5. Frequently asked questions

What is the ChatGPT Google ad scam?

The ChatGPT Google ad scam is a cyberattack that uses sponsored search results to redirect users to a malicious chatbot interface. According to ZDNET, the attack is convincing because it opens within the authentic ChatGPT domain while keeping users logged into their existing accounts.

At-a-Glance: ChatGPT Malware Scam Details
Traffic Source
Sponsored Google search ads
Appeared As
Custom GPT named Plus 5.6
Fake Notice
Service Availability Notice
External Host
Google Sites
Malware Delivery
Windows PowerShell commands
What you'll get

By following this guide, you will learn how to identify fake ChatGPT service notices and protect your workstation from unauthorized PowerShell scripts.

How to spot the fake ChatGPT warning

You can spot the fake ChatGPT warning by checking for an unexpected Service Availability Notice that claims the primary domain has limited availability. The prompt appears under the model title Plus 5.6 and offers an upgrade to Plus or a link to a backup domain.

This setup relies on a custom GPT programmed to return the exact same outage template regardless of what prompt you type into the chat. Testing by ZDNET showed that authentic ChatGPT pages do not present these external backup links.

Watch out

The warning message points to an external, free site hosted on Google Sites that mimics a Cloudflare verification page.

How to avoid the ChatGPT malware trap

To avoid the ChatGPT malware trap, you must bypass sponsored search engine ads and reject any prompts to run command-line scripts. Follow these safety steps whenever you access the platform:

  1. Type chatgpt.com directly into your browser address bar instead of searching for it on Google.
  2. Avoid clicking on any sponsored results displayed at the top of search engine result pages.
  3. Never copy, paste, or run any commands in Windows PowerShell at the request of a website or pop-up.
  4. Verify security checks, keeping in mind that legitimate Cloudflare verifications only ask you to check a box or press a button.
  5. Treat any links provided by a chatbot with the same caution you would apply to a link from an unknown stranger.

How tech platforms are addressing the ChatGPT malware threat

Google is addressing the ChatGPT malware threat by deactivating associated advertiser accounts and deploying Gemini to detect and block malicious ads. A Google spokesperson told ZDNET that malvertising has no place on Google and that defenses are continually updated.

Despite automated enforcement, variations of the ad campaign can occasionally slip through to search results. Roman Oliinyk, CEO of PayCore Media Inc, noted that legitimate security checks never require typing on a keyboard, making PowerShell instructions a definitive sign of an attack.

Frequently asked questions

How does the ChatGPT malware scam start?
The ChatGPT malware scam begins when a user searches for ChatGPT on Google and clicks on a sponsored ad result. This malicious ad redirects the user to a fake interface hosted on the official ChatGPT domain.
What is the Plus 5.6 model in ChatGPT?
The name Plus 5.6 is a deceptive title used by scammers for a malicious custom GPT on the official ChatGPT platform. Legitimate ChatGPT model naming conventions do not include a version 5.6, making this a key indicator of a scam.
How does the fake ChatGPT site install malware?
The fake ChatGPT site directs users to an external website hosted on Google Sites that mimics a Cloudflare security check. This page instructs the user to copy and run a command in Windows PowerShell, which installs the malware on their computer.
Does a real Cloudflare check ask you to run PowerShell commands?
No, a real Cloudflare security check never requires you to run commands on your keyboard or computer terminal. According to security experts, legitimate verifications on ChatGPT or other sites will only ask you to click a button or check a box.
How can I safely access ChatGPT?
To safely access ChatGPT, you should always type chatgpt.com directly into your web browser's address bar. Avoiding search engine results, especially sponsored advertisements, prevents you from landing on malicious custom GPTs.

Sources: ZDNET

Want your brand to be the answer AI gives?

See how ready your website is for ChatGPT, Gemini and Perplexity, free, in about ten seconds.

Related: How to get your brand cited by ChatGPT