Custom GPT Scam: The Fake ChatGPT Backup That Leads to a Malware Download

A ChatGPT search opens a familiar page, but the assistant says you need a backup service. The custom GPT scam makes that small detour matter.

The address looks reassuring. The conversation feels ordinary. Then a verification request asks you to do something a chatbot should never need.

Illustrative reconstruction of a community GPT directing a visitor to a fictional backup page

Overview

A real platform can host an untrustworthy conversation

This campaign uses an attacker-controlled custom GPT as a stepping stone. The familiar ChatGPT domain supplies reassurance before the conversation redirects visitors elsewhere.

ChatGPT and OpenAI are not the scam. The deception comes from a malicious community-created assistant, the promotion leading to it, and the external verification page.

The crucial distinction is between visiting a genuine platform and trusting everything another person publishes there. Those are different decisions.

Security researchers documented the malicious route

Huntress documented a custom GPT campaign using the label Plus5.6, a service-unavailable pretext, and a fake verification page that led to remote-access malware.

The researchers connected at least 40 incidents to related infrastructure, but confirmed custom GPT origins in only two. Those figures should not be treated as interchangeable.

Island also investigated sponsored-search and custom GPT abuse. These findings establish an actual malware-delivery mechanism, not merely an unpopular chatbot or a confusing subscription offer.

The dangerous request happens after the reassuring page

  • A search promotion leads to a community-created GPT rather than the service entry point the visitor expected.
  • The assistant invents an availability problem and offers a backup destination.
  • The destination presents an apparent browser or connection verification.
  • The visitor is persuaded to execute instructions outside the browser.
  • That action can install malware with remote-access capabilities.

The images here are nonfunctional reconstructions with fictional addresses. They illustrate the change in trust, not the appearance of a currently active attacker page.

Why the ChatGPT Address Is Not the Whole Safety Check

You may already know to avoid misspelled domains. This attack is unsettling because that useful habit does not catch the first part.

A community GPT can be reached through the genuine service. Its creator supplies its identity and behavior; a familiar interface does not make that creator trustworthy.

Think about a malicious post on a real social network. The platform address is authentic, while the person behind the post can still be lying.

The same separation matters here. A message inside a chatbot conversation is not automatically an official service-status announcement.

A model-like label can muddy the distinction further. Plus5.6 was the label used in the investigated campaign, not proof of an official OpenAI release.

Readers should not need to memorize that particular label. An attacker can change a display name faster than people can circulate a warning about it.

The durable warning sign is the request: leave this conversation, trust this supposed backup, and complete a verification that changes what your computer does.

It also helps to separate service availability from account access. A real outage does not create a reason to run unexplained commands supplied by a stranger.

How the Custom GPT Scam Works

Step 1: A search result puts the wrong assistant in front of you

The documented route began with sponsored search. Someone looking for ChatGPT could reach an attacker-created assistant while believing they had opened the ordinary service.

Search position is not a security review. An advertisement can be relevant to your search and still send you into a deceptive experience.

The visitor arrives ready to type a question, not investigate who created the assistant. That expectation gives the opening message considerable room to mislead.

A useful habit is to open the service through a saved bookmark or its independently located official entry point, then check which assistant you selected.

Step 2: The assistant claims the normal service is unavailable

Instead of answering normally, the malicious assistant presents an availability notice. The proposed solution is a backup page outside the conversation.

This is a convenient excuse because it explains away the unusual behavior. A broken service seems like a reason to accept a workaround.

But the message is still content supplied through an untrusted assistant. It has not become a system instruction simply because it sounds administrative.

Before following it, ask why an unknown community builder would be responsible for restoring access to the entire service.

Step 3: The backup page changes the subject to verification

The external destination in the reported chain displayed a fake CAPTCHA-style check. Familiar verification language made the next demand seem like a routine obstacle.

The real service and the supposed backup now occupy different origins. The trust earned by the first page should not travel automatically with the click.

A page using a familiar logo, shield, or security phrase can still be controlled by the attacker. Appearance alone does not authenticate its instructions.

The research described Google Sites hosting and Cloudflare-style imagery. Neither legitimate service was the author of the fraudulent verification request.

Nonfunctional reconstruction of a fake verification screen with executable text deliberately omitted

Step 4: A web check becomes an operating-system action

The attack asks the visitor to take instructions out of the webpage and execute them locally. This technique is commonly called ClickFix.

The name matters less than the boundary being crossed. Reading a website is different from telling your computer to run what that website supplies.

Do not paste verification text into Run, Terminal, PowerShell, or another command interface. A normal human-verification challenge does not need that access.

We have omitted executable instructions from the illustration. There is no benefit to testing the payload to decide whether the page is suspicious.

Step 5: The promised fix delivers something else

In the investigated chain, executing the supplied instruction led to remote-access malware. The victim thought they were restoring a chatbot, not installing outside control.

That does not mean every visitor who saw the page was infected. What happened on the device matters, particularly whether instructions were actually executed.

The immediate response should therefore follow your actions. Closing a page and responding to a potentially compromised computer are different levels of cleanup.

If this happened on a work device, tell your security team what you did. A precise timeline is more helpful than guessing whether anything installed.

The Checks That Matter More Than the Name Plus5.6

Check the creator, not just the conversation title

Look for the distinction between the service itself and a community-created assistant. A polished name or technical-sounding version number does not settle that question.

A builder description can provide context, but it is not permission to follow arbitrary off-site instructions. Evaluate the actual request separately.

If you wanted the standard chat experience, return through your usual entry point. You do not need the suspicious assistant to tell you how.

Notice when the task changes

You started by asking a question. Now you are being asked to visit another site, copy hidden text, or use a system utility.

That change deserves a pause even if every previous screen looked convincing. The requested action carries more weight than the surrounding branding.

Security vocabulary can disguise this shift. Words such as verification, connection, availability, and protection describe an excuse, not evidence that the action is safe.

Do not use a disappearing page as reassurance

Huntress reported removal of one malicious GPT and appearance of another during its investigation. The specific links described there may no longer be available.

A removed listing does not undo anything already executed. Conversely, an unavailable page is not proof that your own computer was compromised.

Keep the old URL or browser-history entry for your report. Do not search for a replacement copy just to reproduce the experience.

Did You Only Open It, or Did You Run Something?

Start with this practical distinction. It helps you avoid both unnecessary panic and a response that is too small for what occurred.

If you only read the conversation, close it and report the assistant through the platform. Merely encountering suspicious content does not establish malware execution.

If you opened the backup page but refused its instructions, record the destination and close it. Review any permissions or downloads you accepted there.

Copying text is not the same as executing it. However, clear that clipboard content so it cannot be pasted accidentally into another application.

If you pasted text into a system utility but are unsure whether it ran, treat the device as potentially affected and seek qualified help.

A disappearing window, a blank response, or no visible error is not a reliable test. Malicious activity does not have to announce itself.

If you entered credentials on an outside page, handle those separately. A password exposure can require account protection even without any installed malware.

Write down the order of events before memory becomes fuzzy. Include the ad, GPT name, destination, permissions, downloads, and any action outside the browser.

What to Tell IT Without Replaying the Attack

If you need help, describe the visible action in ordinary language. Saying you pasted text into a Run window is more useful than guessing a malware name.

Include whether you pressed Enter, approved a prompt, or saw a file download. If you cannot remember, say so instead of filling in the gap.

Do not reopen the destination to collect missing details. Your browser history and the time of the event may already give investigators a starting point.

Tell them whether you used the computer afterward for banking, email, or work. That helps prioritize account checks without assuming every account was accessed.

If a colleague received the same promotion, share the warning through your workplace’s reporting route. Avoid forwarding the clickable malicious destination as a casual suggestion to investigate.

The aim is containment and accurate assessment, not proving you recognized the trick. Prompt, honest reporting can make the response easier for everyone involved.

What to Do if You Have Fallen Victim to This Scam

  1. Stop interacting with the supposed backup.

    Do not complete another verification or accept help from the same page. Close its tabs without using any cleanup button it offers.

    If an instruction already ran, disconnect the affected device from networks while arranging assistance. Use another trusted device for urgent account changes.

  2. Get the device assessed.

    For a personal computer, run a reputable malware scan such as Malwarebytes and follow its findings. Update the scanner through its genuine distribution channel.

    A clean scan is useful, but not a guarantee after possible remote access. Professional assessment or a clean reinstall may be appropriate for significant exposure.

    On an employer-managed device, contact IT first. Preserve relevant evidence and let the team decide how to isolate, investigate, and restore it.

  3. Secure accounts from a clean device.

    Change any password entered into the fake site. Review active sessions, sign out unfamiliar devices, and enable available multifactor authentication.

    If malware may have accessed the computer, include important accounts used there. Prioritize email because it can be used to reset other services.

    Check account recovery details and unexpected access grants. Password replacement alone may not address a separate session or application authorization.

  4. Save enough evidence to identify the route.

    Keep the search-ad destination, custom GPT URL, browser history, and approximate time. Screenshots are useful if you already have them.

    Do not execute the instructions again to improve your evidence. Avoid publishing personal information or complete malicious commands in a public warning.

  5. Report the assistant and the promotion.

    Use the reporting controls on the service where you encountered the content. Identify the custom assistant rather than accusing the legitimate platform of running the scam.

    Report any financial loss or unauthorized account activity through the relevant provider. If appropriate, file a cybercrime report with your local authorities.

  6. Reduce repeat exposure without relying on one tool.

    AdGuard can help reduce exposure to malicious advertising and unwanted redirects. It does not make an unknown command safe or replace careful verification.

    Review browser notification permissions and remove permissions granted to the suspicious site. Delete unneeded downloads after preserving the details your investigator requests.

    Be wary of anyone promising instant recovery through another script. A second stranger offering a technical rescue can extend the original compromise.

Frequently Asked Questions

Is the real ChatGPT website part of the scam?

No. Attackers abused a community-created GPT to redirect visitors. A genuine host can contain malicious user-created content without the platform operating the fraud.

Was Plus5.6 an official model announcement?

The label identified the custom GPT in the investigation. Its model-like name should not be interpreted as an official product announcement or endorsement.

Can opening the conversation alone infect my computer?

The documented route depended on additional actions, including executing supplied instructions. Opening the conversation alone does not demonstrate that those later steps happened.

Why would a fake check mention a familiar security company?

Familiar verification imagery makes an unusual request look routine. Judge the action being demanded, especially any instruction to leave the browser and run local commands.

What if I copied the text but did not paste it anywhere?

Copying alone is not execution. Replace the clipboard contents, close the suspicious page, and consider whether you also downloaded files, granted permissions, or entered credentials.

Should I revisit the GPT to see whether it was removed?

No. Preserve the URL you already have and report it. Removal status does not determine whether your earlier actions require device or account cleanup.

The Bottom Line

The custom GPT scam borrows credibility from a real service, then spends it on an unsafe request elsewhere. The off-site verification is the decisive warning.

You do not need to run a command to prove you are human. Stop at that boundary, and get help promptly if you already crossed it.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

SectopRAT in Tampered Audio Software: What Fortinet Found and What to Do

Next

Fake AI Policy Invitation Phishing: How TA419 Steals Microsoft Sessions