Cybercriminals are abusing Google ads and ChatGPT-themed pages to push Windows users into a malware infection that ultimately gives attackers remote access to compromised computers.

 

 

The campaign begins with sponsored search results appearing for queries such as “chatgpt.” Some of the ads directed users to attacker-created content hosted on the legitimate ChatGPT website, making the first stage appear considerably more trustworthy than a conventional fake login or download page.

Researchers found that malicious Custom GPTs could return the same scripted response regardless of what users asked. The response claimed the service was experiencing heavy traffic or availability problems and directed visitors to a supposed backup website.

Following that link moved the victim away from ChatGPT and eventually presented a counterfeit verification page designed to resemble a Cloudflare security check. Instead of completing a normal CAPTCHA, Windows users were instructed to open the Run dialog, paste clipboard content, and execute it.

This is a social engineering technique known as ClickFix. The website quietly prepares a malicious command, while the victim is persuaded to execute it manually under the impression that the step is required to verify that they are human.

Once executed, the command launches PowerShell and begins downloading additional components. Researchers observed several variations of the delivery infrastructure, indicating that the attackers regularly changed domains, payload packaging, and installation methods as the campaign evolved.

The final infection chain could install NetSupport RAT, a legitimate remote administration tool that is frequently abused by cybercriminals. Once deployed maliciously, remote access software can give attackers significant control over an infected Windows computer and allow further activity to take place without requiring the victim to interact with another malicious website.

Researchers tracked a substantial advertising infrastructure behind the campaign. Between late May and August 24, they identified around 850 paid-ad landings connected to 26 ChatGPT-themed destinations and 71 separate Google Ads campaign IDs.

A related investigation also uncovered malicious Custom GPTs used to distribute remote access malware through a fake Cloudflare verification page. Security researchers responded to at least 40 incidents associated with one Google Sites lure, although only two were confirmed to have started directly through interaction with the malicious Custom GPT.

One of the deceptive GPTs was removed after being reported, but the operators quickly returned with another version. The replacement appeared within days, demonstrating how easily attackers can rebuild campaigns that combine legitimate online services with rapidly changing external infrastructure.

Leave a Reply