Post

Fake ChatGPT Ads on Google Lead to Malware Installation

Fake ChatGPT Ads on Google Lead to Malware Installation

🚨 Warning: Fake ChatGPT Ads on Google!

Malvertising campaigns are shifting towards chatbots! 🚀 Google ads for fake ChatGPT pages are leading Windows users into malware traps. Researchers at Island have raised alarms about how a simple Google search for ChatGPT is being manipulated into a malware trap targeting unsuspecting Windows users.

What’s Happening?

Attackers are creating their own content within ChatGPT using CustomGPT and purchasing Google ads to direct users to these malicious sites. This extensive malvertising campaign has involved over 850 paid-ad landings, 26 lookalike ChatGPT destinations, and 71 Google Ads campaign IDs over a three-month period, concluding in August.

How It Works

Once users engage with the attacker-created GPT, they are met with a repetitive message stating that the service is experiencing “high traffic” and are redirected to a supposed “backup domain.” Island has noted that this identical response appeared across conversations from two separate lookalike Custom GPTs over three days.

Anyone who follows the link could be redirected to a counterfeit ChatGPT and Cloudflare verification page, where they are instructed to press Win+R, paste clipboard content, and hit Enter—allegedly to prove they are human.

The ClickFix Trap

Island warns that this is a “ClickFix” trap—a social engineering technique that deceives users into executing malicious commands on their own devices. The instructions trick Windows into running a hidden command that downloads disguised malware onto the computer. Once installed, the malware can infect the system, survive restarts, and secretly communicate with attackers via a Telegram bot.

The malware utilizes a well-known tool called NetSupport RAT, allowing an attacker to remotely control the infected computer as if they were physically present. Researchers have also observed attackers rotating domains and employing various Windows malware-delivery methods, indicating that the scam is not reliant on a single disposable website.

Red Flags for Windows Users

For Windows users, there’s a significant red flag in this campaign: no CAPTCHA or routine website verification should require you to open Windows Run and paste a command. If a website instructs you to press Win + R, paste something, or run PowerShell to prove you are human, do not comply! 🚫 No legitimate CAPTCHA should ask you to execute Windows commands or PowerShell to verify your identity.

For more details, check out the full article: Read full article

This post is licensed under CC BY 4.0 by the author.