New ChatGPT Scam Uses Sponsored Google Links to Install Malware
A new scam involving ChatGPT uses sponsored Google links to direct users to a custom GPT that displays a fake availability notice and can lead them to install malware.
The scam begins when a user searches for “ChatGPT” on Google. Sponsored results appear above authentic search results, and clicking one that looks like a real ChatGPT link can land the user on a custom GPT, a user-generated version of ChatGPT designed for a specific task. In this case, the custom GPT returns the same availability notice no matter what is entered. The notice says, “We’re currently experiencing limited availability on the primary domain. Please choose one of the following options to continue:” It offers an upgrade to a Plus subscription or a link to a backup domain.
The page is convincing because it sits on the actual ChatGPT domain and the user’s account remains logged in if it was before. The only obvious clue is the name “Plus 5.6,” which may not stand out to users unfamiliar with ChatGPT model naming conventions.
If the user clicks the link in the response, it leads to a free site hosted on Google Sites that is not a ChatGPT domain. The page presents a fake Cloudflare verification and tells the user to paste and run a command in Windows PowerShell. Running that command installs malware on the computer, according to ZDNet.
ZDNet tested the process and clicked the first result after a simple search for ChatGPT, landing on one of the scams. No matter what was typed, the same “limited” response and link appeared. A ZDNet editor tried the same process and received the normal ChatGPT, indicating that not all sponsored results are part of the scam.
To avoid the scam, users can type ChatGPT.com directly into a browser instead of searching for it. They should avoid clicking sponsored Google links, which have a history of being malicious; Google has deployed Gemini to detect and block bad ads, according to ZDNet. Users should also never paste and run a command unless they are certain what it will do, especially when a link or popup instructs them to do so.
Roman Oliinyk, CEO and founder of PayCore Media, Inc., a network security specialist who has spent 10 years building data-leak protection systems for large US companies, said a real Cloudflare check would never ask users to do anything on their keyboards. “At most,” he said, “it asks you to check a box or press a button.” Oliinyk also recommended treating sponsored results as ads and treating a link from a chatbot as a link from a stranger.
ZDNet said it reached out to Google and OpenAI for comment. Google assured ZDNet it is looking into the matter, while OpenAI had not responded at the time of publication.