For many start-ups and small businesses, ChatGPT is now part of the daily toolkit. That familiarity is exactly what cybercriminals are exploiting, according to new research from cybersecurity firm Huntress.
Huntress researchers uncovered a campaign in which attackers built a fake ChatGPT model called “Plus 5.6” using OpenAI’s Custom GPT feature. The model sat on the genuine chatgpt.com website, and in some cases was promoted through paid Google ads, so employees searching for ChatGPT could be sent straight to it.
Once there, users were told the service was busy and directed to a “backup” site. That site showed a fake security check and asked them to copy a command into their computer. Doing so quietly installed a remote access trojan, giving attackers the ability to see the screen, switch on the webcam and microphone, search through files and install more malware, including tools that could open the door to wider attacks on a company network.
The malware was also built to survive. It checked for the company’s domain and antivirus set-up, hid behind genuine, signed software from well-known vendors and set up two separate ways to restart itself. In one case, Microsoft Defender caught the installer, but only after it had already run, and the infection continued.
Huntress has responded to at least 40 incidents linked to the campaign so far, two of which were confirmed to have come through the fake GPT. OpenAI took the original model down after Huntress reported it, yet a new one appeared within two days.
More from Cybersecurity
- GPT-6 Astra Attempted Supply Chain Attacks In 29% Of Tests – Should Businesses Be Worried?
- Browser Extensions Could Now Hijack Your AI Assistant Even When It Gets Everything Right
- UK Firms Hit By Over 1,500 Cyber Attacks A Week As Ransomware Nearly Doubles Globally
- Anthropic Discloses Fourth Unauthorised Claude Access Incident – Is The Security Industry Prepared For AI Breaches?
- Bot Traffic Vs Human Traffic: What Decodo Found
- SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now The Leading Path Into The Enterprise
- Your Smart TV Might Be Eavesdropping: Behind The Security Flaws Compromising Your Living Room
- Reflectiz Launches Agentic Pentesting For Websites: Up To 10x Coverage Vs Conventional Pentests
What Businesses Can Do Now
Huntress’s findings point to a few practical steps for smaller organisations. Staff should be told plainly that no real website asks them to paste commands to prove they are human, and that a sudden “service unavailable, use our backup site” message is a red flag.
Teams should access AI tools through bookmarked links or official apps rather than search ads. And businesses should make sure someone is actively watching for suspicious activity on their devices, because as this campaign shows, antivirus alone may react too late.
