Beware This ChatGPT Knockoff That Hijacks Your Webcam

A malicious Custom GPT and fake CAPTCHA are being used to deliver a Remote Access Trojan that can spy on your screen, webcam, microphone, and files.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

You search for ChatGPT on Google, click on the top result, and land on ChatGPT.com, the real website. However, the chatbot tells you that the service isn’t working and guides you through a backup site, where you encounter a very familiar “verify you’re a human” check. It tells you to paste a quick command into your computer. And just like that, you’ve unknowingly given hackers a way into your computer.

Security research firm Huntress has found attackers abusing ChatGPT’s Custom GPT feature to trick victims into installing malware on their systems. The malware ultimately deploys a Remote Access Trojan (RAT), giving attackers extensive control over an infected computer, including access to its camera, microphone, system audio, browser activity, and files.[1]

If you’re a regular ChatGPT user, you should read on to learn all the important details about this new attack vector and the steps you can take to stay safe from malware.

In this article
How the fake ChatGPT attack works
New disguise, same malware
How this RAT can take control of your computer
What can you do to protect yourself
The bottom line

How the fake ChatGPT attack works

The attack starts when someone searches for ChatGPT on Google. At the top of the results is a sponsored link, which is a paid ad the attackers have bought. Since this ad sits above the normal results, it’s more likely to be the first thing people click.

The sponsored Google result can create a false sense of security. When an ad appears at the top of Google, it can feel as though the platform has already checked that the website or service behind it’s legitimate. But scammers can buy ads that impersonate real companies and use the credibility of the platform to make their scams look more convincing.

Meet 'Plus 5.6,' ChatGPT's fake new model

The link doesn’t go to a fake website, but to the legitimate ChatGPT.com itself, specifically to a Custom GPT page. Custom GPTs are a ChatGPT feature that lets people build their own personalized chatbots for specific purposes and publish them on OpenAI’s website.

The attackers built a Custom GPT and named it “Plus 5.6” so that it looks like a legitimate ChatGPT model. The only small giveaway is a line saying “made by Community Builder,” but that’s easy to miss.

The redirect to Google Sites

According to Huntress’s report, no matter what the user types into this Custom GPT, the fake chatbot gives the reply “Service Availability Notice,” saying that ChatGPT is having trouble on its main site.

Huntress Fake ChatGPT error malware

It urges the user to either upgrade to a paid plan or continue on a backup domain. Naturally, most users choose the backup domain option, which then takes them to a page hosted on Google Sites, another trusted platform.

The ClickFix trick

The Google Sites page first loads a Cloudflare “prove you’re a human” check, something that’s a common occurrence, so users don’t suspect it. But instead of clicking a box to prove they’re human, the page tells the user to copy a command and paste it into the computer’s terminal.

Huntress Fake ChatGPT error malware

This is called ClickFix, a technique where the victim installs the malware themselves by running commands on their computer, which is how the attack gets past security protections that might otherwise block an automatic download. This is similar to the ClickFix technique used in the WordlistLoader malware discovered by researchers at Gen Threat Labs in late August.

A signed program with a poisoned file

When the user pastes the command, it reaches out to the attacker’s server and pulls down a heavily disguised script, which silently installs a program posing as an advanced printer configuration reader.

The installer itself includes a genuinely digitally signed program from Canon, the camera and printer company. Security software often tends to trust signed software from known companies. However, the attackers have quietly placed a tampered version of one of the files alongside it. When the Canon app starts, it loads this tampered file, which pulls in the attacker’s code. This is known as DLL side-loading.

Layers upon layers

The next piece of malware is hidden in an audio file, .wav. It starts with real sound, but somewhere through the audio, the attackers have replaced part of it with scrambled code. After this comes a custom-built encrypted storage file that holds the final payload.

Each layer exists to hide the previous one, and much of the malware runs directly in the computer’s memory rather than appearing as a normal file on disk, making it harder for security tools to detect. Huntress counted eight stages between the initial ClickFix command and the final RAT payload.

New disguise, same malware

Huntress reported this fake chatbot to OpenAI, and the company took it down around September 25. However, just two days later, on September 27, security researchers found a new “Plus 5.6” Custom GPT active on OpenAI’s website.

The second wave swapped Canon’s signed program for one from Stardock and hid the malware inside a fake Microsoft software package instead of an audio file. The RAT inside was exactly the same.

In other words, the attackers changed the disguise, but not the final malware. Huntress says it found a third disguised installer on the attacker’s server and expects there to be more variations.

How this RAT can take control of your computer

The final payload is a Remote Access Trojan, or RAT, a type of malware that gives attackers extensive remote control over your system. Before the RAT starts spying on your computer, it runs various checks and takes an inventory of your system.

It checks which antivirus programs are installed and whether Microsoft Defender is switched on. The RAT also checks whether the computer is part of a company network and which ports are open, which could give attackers opportunities for lateral movement.

Besides this, it checks all installed software, along with a detailed hardware profile. This preliminary check also helps the RAT avoid virtual machines where security researchers might be testing or studying the malware.

Here’s what can happen if your system has been infected by a RAT:

  • Screen control: This allows attackers to run remote desktop sessions, watch your screen, and operate the computer directly.
  • Camera and sound: They can capture your webcam, microphone, and whatever audio your computer is playing, potentially seeing and hearing you and your surroundings.
  • Browser hijacking: The malware can recognize 17 different web browsers, such as Chrome, Edge, and Yandex, determine which one is your default browser, and open it. Browsers often hold saved logins and active sessions, which can give hackers opportunities to steal credentials and hijack sessions.
  • Access to system files: The malware also includes a built-in file manager with a search tool that allows threat actors to look inside files across your entire system, rather than merely seeing their names. This means they could search for terms like “password,” “invoice,” or “bank” to find personally identifiable information saved on your computer.
  • Future attacks: A RAT can also download and run additional malicious programs, potentially leading to further data theft or even ransomware attacks.

If you have saved sensitive information on your computer, the attackers could potentially get to it. This might include details like your phone number, email address, Social Security number, bank account numbers, passwords, and more. These details could then be used to target you with convincing phishing scams or financial fraud. Attackers might even sell the information on the dark web and attempt identity theft.

Besides spying on you, the malware also makes sure that it stays up and running by adding an entry to the Windows startup list. This launches the program automatically whenever you log in to your system. It also creates a scheduled task, a Windows feature that runs a program at set intervals.

What can you do to protect yourself

Since this is a ClickFix-style attack, the malware isn't automatically downloaded onto your computer until you run the malicious command yourself.

  1. Open the website directly: The attack starts when you click on a sponsored ad link rather than visiting the ChatGPT website or app directly. Use the address bar to type in the website name or use bookmarks to access AI chatbots instead of relying on sponsored search results.
  2. Never copy-paste commands into your computer: No legitimate “I am not a robot” check will ever ask you to copy or paste a command into PowerShell or your terminal. This is the key trick that makes ClickFix attacks work. Be wary of any website asking you to do this.
  3. Use a reliable antivirus program: While this particular malware uses several techniques to evade detection, security software can still detect and block malicious components. Make sure to keep your antivirus updated, as this can improve your chances of catching the malware.
  4. Change your passwords if you think you've been infected: Disconnect the computer from the internet and run a full antivirus scan. Then change the passwords for sensitive accounts, particularly banking, email, social media, and other important services, using a different trusted device. A password manager can help you generate and store strong, unique passwords for those accounts. Also enable two-factor authentication wherever possible.
  5. Cover your webcam when you’re not using it: Most modern computers come with a webcam sliding cover. Make sure the webcam slider is shut when you’re not actively using it. Similarly, disable microphone access on your system when you’re not using it.
  6. Get an identity theft protection service: If you save personal information on your computer, it can make sense to use an identity theft protection tool. These services can monitor known breach databases and parts of the dark web for your leaked information.

The bottom line

While millions of users rely on AI tools like ChatGPT for their day-to-day work, attackers are exploiting that trust and turning a legitimate ChatGPT feature into a delivery mechanism for malware that can take extensive control of your computer.

To stay safe, only open apps and websites through official links or bookmarks, and avoid any website instructing you to copy and paste commands into your computer.

If you think you’ve already been infected, disconnect from the internet, change your passwords, and run a full antivirus scan. Also consider using an identity theft protection service to look for signs that your information has been exposed.

#1 Antivirus Protection From an Award-Winning Brand You Trust
5.0
Editorial Rating
Claim Deal
On Norton 360 Antivirus's website
2026 Editors’ Choice
Best All-In-One Antivirus
Antivirus Software
Norton 360 Antivirus
PROMOTION: Save Up to 76%
  • Our #1 rated antivirus that scores 18/18 on AV-TEST across Windows, macOS, and Android, verified across multiple test rounds
  • Passed every malware, drive-by download, and phishing detection test we ran, quarantining threats automatically
  • Backed by a 100% Virus Protection Promise: if Norton can't remove a virus, you get your money back

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix