Fake ChatGPT Model Tricks Users Into Installing Spyware And Businesses Are In The Firing Line

For many start-ups and small businesses, ChatGPT is now part of the daily toolkit. That familiarity is exactly what cybercriminals are exploiting, according to new research from cybersecurity firm Huntress.

Huntress researchers uncovered a campaign in which attackers built a fake ChatGPT model called “Plus 5.6” using OpenAI’s Custom GPT feature. The model sat on the genuine chatgpt.com website, and in some cases was promoted through paid Google ads, so employees searching for ChatGPT could be sent straight to it.

Once there, users were told the service was busy and directed to a “backup” site. That site showed a fake security check and asked them to copy a command into their computer. Doing so quietly installed a remote access trojan, giving attackers the ability to see the screen, switch on the webcam and microphone, search through files and install more malware, including tools that could open the door to wider attacks on a company network.

The malware was also built to survive. It checked for the company’s domain and antivirus set-up, hid behind genuine, signed software from well-known vendors and set up two separate ways to restart itself. In one case, Microsoft Defender caught the installer, but only after it had already run, and the infection continued.

Huntress has responded to at least 40 incidents linked to the campaign so far, two of which were confirmed to have come through the fake GPT. OpenAI took the original model down after Huntress reported it, yet a new one appeared within two days.

What Businesses Can Do Now

 

Huntress’s findings point to a few practical steps for smaller organisations. Staff should be told plainly that no real website asks them to paste commands to prove they are human, and that a sudden “service unavailable, use our backup site” message is a red flag.

Teams should access AI tools through bookmarked links or official apps rather than search ads. And businesses should make sure someone is actively watching for suspicious activity on their devices, because as this campaign shows, antivirus alone may react too late.