You can check the website address, recognise the company behind it and still end up following instructions from a criminal. That is the uncomfortable part of a malware campaign uncovered by security researchers at Huntress, because the first step can happen on the real ChatGPT website.
For anyone who has spent years telling friends and family to check the link before clicking, this needs a slightly better explanation than “be careful online”. Checking the address still matters, but we also need to pay attention to who created the content and what they are asking us to do.
How the scam works
According to Huntress’s investigation, attackers created a Custom GPT called “Plus 5.6”, which directed people to a supposed backup site. That external page, hosted on Google Sites, presented a fake Cloudflare verification check and persuaded visitors to run a command on their Windows computer, triggering a malware installation.
Custom GPTs are customised assistants created by users. Their presence on ChatGPT does not make them an official OpenAI product, although a convincing name and familiar interface can make that distinction easy to miss.
Huntress says OpenAI removed the reported GPT on 25 September, but researchers found a replacement on 27 September. The malware they examined could provide remote access, search files and capture camera and microphone input.
The reported infection involved running the malicious command. Simply visiting ChatGPT was not the infection step described by the researchers.
When proving you’re human becomes the trap
This technique is known as ClickFix. Microsoft’s analysis describes scams that disguise malicious instructions as a way to solve a technical problem or complete a verification check.
The useful warning sign is the request to leave the browser and run something on your computer. A page asking you to open Windows Run, PowerShell or Terminal and paste a command to prove you are human should bring the whole process to a stop. Microsoft Security Blog
Most people trying to use an AI assistant are thinking about the task they need to finish. If a page says the service is busy and offers a way around the problem, it arrives at exactly the moment they are likely to be impatient. Add a familiar security logo and the instruction starts to look like another irritating hurdle between them and their work.
I think that is why telling people they should have known better is such an unhelpful response. We need advice that identifies the dangerous request clearly enough for someone to recognise it while distracted, busy or frustrated.
Your client’s information could be on that laptop too
The South African relevance is practical, although the research reviewed for this article does not establish that South Africans were affected by this particular campaign.
Think about what could be open on a small-business owner’s laptop during an ordinary working day: email, supplier invoices, a client proposal, a spreadsheet with customer details and access to the online store. An incident involving that machine could have consequences for people who never interacted with the suspicious page themselves.
That also changes how I think about confidentiality. We often discuss AI privacy in terms of whether we should upload a document to an assistant, which is a worthwhile conversation, but protecting the computer holding the document matters just as much. Keeping a proposal out of an AI chat does not protect it from someone who gains access to the device itself.
That is a possible consequence of device compromise, not evidence that client proposals were stolen in this campaign.
What to do if you encounter it
If a verification page asks you to run a command, close it without following the instructions. Return to the service through an address or bookmark you already trust, and report the suspicious content through the platform’s reporting tools.
If you have already executed the command, closing the browser is not an adequate response. Disconnect the affected computer from Wi-Fi or Ethernet and contact your IT provider or workplace support team. Explain what happened and avoid using that device for sensitive work until it has been assessed.
New Zealand’s National Cyber Security Centre guidance recommends disconnecting an infected device, removing the malware and securing accounts afterwards, including resetting passwords, ending existing sessions and checking account activity. For a work computer, coordinate recovery with IT rather than attempting to clean it up quietly yourself.
I use AI because I want to get work done with less friction, and I suspect that is true for most people reading this. But an instruction deserves scrutiny even when it appears inside a product we use every day. If getting back to your conversation suddenly requires pasting a command into your computer, take the interruption and stop.
