- Malicious sponsored Google ads lead to fake ChatGPT interfaces.
- The scam uses custom GPTs to mimic the official platform.
- Fake Cloudflare checks prompt users to run malware commands.
- Always type the official ChatGPT web address directly.
In this guide
What is the ChatGPT Google ad scam?
The ChatGPT Google ad scam is a cyberattack that uses sponsored search results to redirect users to a malicious chatbot interface. According to ZDNET, the attack is convincing because it opens within the authentic ChatGPT domain while keeping users logged into their existing accounts.
- Traffic Source
- Sponsored Google search ads
- Appeared As
- Custom GPT named Plus 5.6
- Fake Notice
- Service Availability Notice
- External Host
- Google Sites
- Malware Delivery
- Windows PowerShell commands
By following this guide, you will learn how to identify fake ChatGPT service notices and protect your workstation from unauthorized PowerShell scripts.
How to spot the fake ChatGPT warning
You can spot the fake ChatGPT warning by checking for an unexpected Service Availability Notice that claims the primary domain has limited availability. The prompt appears under the model title Plus 5.6 and offers an upgrade to Plus or a link to a backup domain.
This setup relies on a custom GPT programmed to return the exact same outage template regardless of what prompt you type into the chat. Testing by ZDNET showed that authentic ChatGPT pages do not present these external backup links.
The warning message points to an external, free site hosted on Google Sites that mimics a Cloudflare verification page.
How to avoid the ChatGPT malware trap
To avoid the ChatGPT malware trap, you must bypass sponsored search engine ads and reject any prompts to run command-line scripts. Follow these safety steps whenever you access the platform:
- Type chatgpt.com directly into your browser address bar instead of searching for it on Google.
- Avoid clicking on any sponsored results displayed at the top of search engine result pages.
- Never copy, paste, or run any commands in Windows PowerShell at the request of a website or pop-up.
- Verify security checks, keeping in mind that legitimate Cloudflare verifications only ask you to check a box or press a button.
- Treat any links provided by a chatbot with the same caution you would apply to a link from an unknown stranger.
How tech platforms are addressing the ChatGPT malware threat
Google is addressing the ChatGPT malware threat by deactivating associated advertiser accounts and deploying Gemini to detect and block malicious ads. A Google spokesperson told ZDNET that malvertising has no place on Google and that defenses are continually updated.
Despite automated enforcement, variations of the ad campaign can occasionally slip through to search results. Roman Oliinyk, CEO of PayCore Media Inc, noted that legitimate security checks never require typing on a keyboard, making PowerShell instructions a definitive sign of an attack.
Frequently asked questions
How does the ChatGPT malware scam start?
What is the Plus 5.6 model in ChatGPT?
How does the fake ChatGPT site install malware?
Does a real Cloudflare check ask you to run PowerShell commands?
How can I safely access ChatGPT?
Sources: ZDNET
Want your brand to be the answer AI gives?
See how ready your website is for ChatGPT, Gemini and Perplexity, free, in about ten seconds.