Will it run?
Security

New ChatGPT scam uses Google ads to deliver malware

By Nadia Ksiazek Clawpit staff

The campaign starts with an innocent search for "ChatGPT" on Google. The sponsored result at the top of the page leads to a URL that looks legitimate but actually lands on a Custom GPT — a user-created version of the chatbot — named "Plus 5.6." No matter what you type, the model always returns the same "Service Availability Notice" inviting you to upgrade to a Plus subscription or switch to a backup domain. The link points to a site hosted on Google Sites that displays a fake Cloudflare verification screen, which asks you to copy and run a PowerShell command in a Windows terminal. Executing the command installs malware.

What makes the trap convincing is that the browser address bar shows the real chatgpt.com domain, and if you were logged in, you stay logged in. There is no visual indication that you are interacting with a custom model rather than the official interface, apart from the name "Plus 5.6" appearing in the chat header. Anyone unfamiliar with model naming conventions would have no reason to suspect anything. The ZDNET reporter who broke the story tried it himself: a simple search surfaced the sponsored result as the first hit, and he landed directly in the trap. His editor, by contrast, got the regular chatbot, indicating the campaign does not blanket every sponsored slot but targets selectively.

Google said: "We have disabled several advertiser accounts linked to this specific campaign, and we continuously update our defenses, including using Gemini to detect malicious ads." Roman Oliinyk, chief executive and founder of PayCore Media Inc. and a network security expert with a decade of experience building data-leak prevention systems for large U.S. companies, said: "A genuine Cloudflare challenge never asks you to type anything on your keyboard; at most you are asked to tick a box or press a button." He added: "Treat sponsored results as advertisements, pure and simple, and treat any link that comes from a chatbot as if it came from a stranger."

The practical advice is straightforward: type chatgpt.com directly into the address bar instead of searching on Google. Avoid clicking sponsored results, or at least treat them with heightened suspicion. And never copy and execute a command in a terminal unless you are one hundred percent certain what it does — especially if a pop-up or a chatbot link told you to do it. OpenAI had not responded to a request for comment at press time. (Disclosure: Ziff Davis, ZDNET's parent company, filed a lawsuit against OpenAI in April 2025 alleging copyright infringement in the training and operation of its systems.)