AI News Feed
Market watch
Cybersecurity

Real ChatGPT Page Used to Push Malware via Fake ‘Plus 5.6’ Bot

Attackers used a real ChatGPT Custom GPT to send users to a fake security check and a malicious Windows command, Huntress researchers found.

According to the report, attackers abused ChatGPT’s Custom GPT feature to create the bot. The name “Plus 5.6” was chosen to sound like an official OpenAI model. Because Custom GPTs are hosted on ChatGPT.com, anyone opening the link would see a legitimate ChatGPT address in the browser. The page was not a spoofed domain that could be spotted by checking the URL.

The fake bot then sent users to a fake security check. The check tricked users into running a malicious Windows command. The command could install malware that could access files, the screen, the webcam, the microphone, and more, according to the report.

Android Authority said the campaign makes scam detection harder. Spotting a sketchy download once meant looking for misspelled websites, strange pop-ups, and other obvious red flags. Those signals are less useful when the scam begins on a website the user already trusts.

Researchers at Huntress found the activity, with TechRadar also reporting on the findings, according to Android Authority. The report described the attack as using a real ChatGPT page to lend legitimacy to the fake “Plus 5.6” bot before moving users to the fake security check.