Fake ChatGPT ads show attackers abusing AI workflows, not just AI brands


AI lure
Researchers reported a fake “Plus 5.6” ChatGPT-style lure that moved users toward ClickFix execution prompts.
850+ landings
Island-linked reporting identified more than 850 paid-ad landings, 26 lookalike ChatGPT destinations and 71 Google Ads campaign IDs.
Endpoint risk
The reported chain included PowerShell execution, MSI installation, DLL sideloading, persistence and remote access trojan delivery.
A malvertising campaign reported by Island and other security researchers used sponsored Google search ads, ChatGPT lookalike pages and fake Custom GPT-style interactions to steer users toward ClickFix malware prompts. The campaign exposed a gap in defenses that rely heavily on domain reputation or basic brand-impersonation checks.123
Its significance is not just that it impersonated ChatGPT. Researchers described a delivery chain in which paid ads and convincing AI-themed pages moved users through trusted or familiar surfaces before presenting fake verification steps that instructed them to run commands on Windows systems.14 For security operations leaders, the case shows how attackers can turn AI interaction layers into malware-routing infrastructure while keeping the early stages close to legitimate brands, platforms and user expectations.
Island’s reporting, as summarized by iTechGuides, identified more than 850 paid-ad landings, 26 lookalike ChatGPT destinations and 71 Google Ads campaign IDs connected to the cluster.3 Lumien also reported that the activity involved sponsored Google Ads leading into a real chatgpt.com Custom GPT-style experience, then onward to Google Sites or fake Cloudflare-themed ClickFix pages. Lumien said Google suspended advertiser accounts associated with the campaign.1
Earlier AI-themed malware lures often centered on counterfeit installers, browser extensions or downloadable “AI tools.” This cluster appears to mark a shift. The attacker-controlled path did not rely only on persuading users to download a fake ChatGPT application. Instead, users were reportedly steered through interactions that mimicked or abused AI product workflows, including a lure branded as “Plus 5.6.”14
Aardwolf Security argued that the case should challenge the habit of trusting a destination simply because it begins on a reputable domain. The concern is that if a user first encounters a lure through a legitimate chatgpt.com-hosted Custom GPT surface, conventional controls may treat the session as lower risk even when the conversation or prompt flow later points the user toward attacker-controlled infrastructure.2
That model matters because AI interfaces are increasingly treated as productivity layers, not ordinary websites. Users expect them to generate instructions, ask for confirmation and guide multi-step workflows. Attackers can exploit that trust by making malicious instructions feel like part of an interactive support or setup process rather than a classic phishing redirect.
Researchers described a familiar ClickFix pattern: a user lands on a verification-style page, often styled to resemble a Cloudflare check, and is instructed to perform manual steps that execute code locally.46 In reported variants, the path involved fake CAPTCHA or verification prompts, PowerShell execution and Windows malware delivery.4
The post-click infection chain described by iTechGuides included MSI installation, DLL sideloading through signed host binaries, persistence and remote access trojan capabilities.5 Huntress-linked reporting cited by iTechGuides also described DLL sideloading and RAT delivery claims after the fake “Plus 5.6” lure moved users through the ClickFix sequence.4
ClickFix attacks are difficult for purely perimeter-focused defenses because they induce the user to become part of the execution chain. The malicious page may not need to exploit a browser vulnerability. Instead, it presents instructions that persuade the user to paste or run a command, shifting the decisive step from web content delivery to endpoint execution.
The campaign combined three trust signals that can weaken conventional detection: sponsored search placement, recognizable AI branding and legitimate web infrastructure. A user searching for an AI service may assume a sponsored result is vetted. A security stack may score a real platform domain as reputable. A fake verification page may resemble the routine anti-bot checks users see across the web.123
That combination creates a problem for controls that look for single-point indicators. Blocking obvious typo domains may not catch a chain that starts with a paid ad and passes through a trusted AI surface. Reputation filtering may not flag the first interaction if it occurs on a legitimate domain. Brand monitoring may identify lookalike pages, but only after the campaign has moved across multiple ad IDs, landing pages and backup infrastructure.23
Practitioner discussion on Reddit’s r/Malware also focused on the risk of sponsored-search results and the limits of initial-domain checks, with users pointing to ad blocking and greater skepticism of promoted links as practical mitigations.7 While community reaction is not a substitute for telemetry, it reflects a broader operational lesson: the first visible domain is no longer enough to determine whether the full user journey is safe.
Security operations leaders should treat AI-branded malvertising as a user-journey problem, not just a domain-blocking problem. The reported chain moved across ads, lookalike pages, Custom GPT-style interactions, Google Sites backup pages, fake verification pages and endpoint execution steps.134 Each stage may look less suspicious in isolation than the complete sequence.
Detection teams should prioritize telemetry that connects the browser and endpoint layers. Useful signals include visits from sponsored search results to newly observed AI-themed domains, redirects from AI product pages to file-sharing or site-builder infrastructure, clipboard or command-paste behavior after a verification prompt, PowerShell launched from user-driven instructions, MSI execution after browser activity, and signed-binary DLL sideloading patterns.45
Organizations should also review how their secure web gateways, endpoint detection tools and security awareness programs handle AI surfaces. A policy that allows trusted AI domains may still need controls for outbound links, prompt-delivered instructions and file execution paths. User guidance should emphasize that legitimate AI services and verification pages should not require copying commands into PowerShell or a Windows Run dialog to prove the user is human.
The reported cluster points to a broader attacker adaptation. As AI platforms become routine work surfaces, their conversational and workflow features can be abused as routing layers. The brand lure remains important, but the larger development is the use of AI-style interaction to make the next malicious step feel authorized, contextual and normal.
For defenders, the lesson is to follow the chain rather than the logo. The campaign shows how paid ads, reputable domains and familiar verification designs can be combined to create a malware path that looks trustworthy until the user is asked to execute code. Security controls that correlate ad provenance, AI-session behavior, redirect paths and endpoint execution will be better positioned than controls that decide trust by domain name alone.

GitHub is unifying Copilot Chat, Copilot Mobile and the Copilot cloud agent into a more persistent agentic coding experience. For enterprise administrators, the immediate question is no longer whether developers can try AI agents, but how default-on agent capabilities should be governed, retained, audited and constrained.

Horizon3 said Anthropic’s Mythos helped identify CVE-2026-61500, a Rejetto HFS session-forgery flaw that can lead to unauthenticated remote code execution. VulnCheck said exploitation began on October 1, underscoring how quickly AI-assisted vulnerability research can move from code review to real-world attack monitoring.

Shopify’s new Canvas workspace lets merchants edit a live rendering of their storefront through Sidekick, moving AI storebuilding closer to direct theme-file modification than conventional no-code design. Its launch limits around third-party themes, app blocks, translations, Markets and rollouts show where developers remain central.

Microsoft AI’s October 1 launch of MAI-Transcribe-2-Streaming, MAI-Voice-2.1 and MAI-Voice-2.1-Flash shows how voice agents are shifting from monolithic AI systems to low-latency pipelines. For developers and enterprise architects, the important change is not just better speech recognition or synthesis, but the separation of voice input, reasoning and voice output into tunable components.
ClickFix
A social-engineering technique that presents a fake error, CAPTCHA or verification page and instructs the user to run commands that install malware.
Custom GPT
A customized ChatGPT-style experience that can guide users through specific prompts or workflows, which attackers may imitate or abuse.
DLL sideloading
A technique in which attackers place a malicious dynamic-link library where a legitimate signed program will load it.
Malvertising
The use of online advertising systems to deliver malicious links, redirects or scams to users.
Comments