TL;DR
  • Attackers created a fake ChatGPT model called “Plus 5.6” on the real ChatGPT website.
  • It sent users to a fake security check that tricked them into running a malicious Windows command.
  • That command could install malware that could access files, the screen, the webcam, the microphone, and more.

There was a time when spotting a sketchy download meant looking for misspelled websites, strange pop-ups, and other obvious red flags. But that gets much harder when the scam starts on a website you already trust. Security researchers have uncovered a malware campaign that does exactly that, using a real ChatGPT page to convince people they’re dealing with an official OpenAI product before redirecting them to a far more dangerous site.

Researchers at Huntress (via TechRadar) found attackers abusing ChatGPT’s Custom GPT feature to create a bot called “Plus 5.6.” The name was chosen to sound like an official OpenAI model, and because Custom GPTs are hosted on ChatGPT.com, anyone opening the link would see a legitimate ChatGPT address in their browser.