AivexaNewsSearch
AI news for builders and product teamsChecked every hour

This new ChatGPT scam tricks you into installing malware – how to spot the trap

Collected Oct 2, 2026

A new scam involving ChatGPT has been reported in which users are directed to a custom GPT that displays a fake "Service Availability Notice" and ultimately leads to malware installation, according to ZDNET.

The scam begins when a user searches "ChatGPT" on Google and clicks a sponsored result that appears to be a link to ChatGPT. Instead of the normal interface, the user lands on a custom GPT — a user-generated, specialized version of ChatGPT — that returns the same availability message regardless of input. According to the report, the message offers an upgrade to a Plus subscription or a link to a backup domain, and includes the name "Plus 5.6." ZDNET states the interaction occurs on the actual ChatGPT domain with the user's account logged in if it was previously.

Clicking the link in the response leads to a free site hosted on Google Sites, where the user is shown a fake Cloudflare verification and instructed to paste and run a command in Windows PowerShell. Running that command installs malware, according to the report. ZDNET said its own test of a ChatGPT search landed on one of the scams, while an editor performing the same process received normal ChatGPT, so it does not appear that all sponsored results are affected.

Roman Oliinyk, CEO and founder of PayCore Media, Inc., who the report describes as a network security specialist with 10 years building data-leak protection systems for large US companies, said a real Cloudflare check would never ask a user to do anything on their keyboard, and at most asks a user to check a box or press a button. He recommended treating sponsored results as ads and treating a link from a chatbot like a link from a stranger.

ZDNET offered safety guidance: type ChatGPT.com directly into the browser instead of searching for it; avoid or be highly suspicious of sponsored Google links; and never paste and run a command without certainty about what it will do. The report also cited Google's deployment of Gemini to detect and block malicious ads.

ZDNET said it reached out to Google and OpenAI for comment. Google assured the publication it is looking into the matter, and OpenAI had not responded at the time of the report.

A disclosure in the report states that Ziff Davis, ZDNET's parent company, filed an April 2025 lawsuit against OpenAI alleging it infringed Ziff Davis copyrights in training and operating its AI systems.

Read at ZDNet · AI

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

This authentic-looking scam starts with a sponsored Google link – and it’s catching people off-guard.