Don't Paste the Command

A fake ChatGPT add-on sat on chatgpt.com, with the real address and the real padlock, and asked people to paste a line of text into Windows. The ones who did handed over the machine. One sentence stops the whole family of attacks.

On September 28, researchers at Huntress published what happened to people who searched Google for "chatgpt" and clicked the sponsored result. It led to a Custom GPT — one of the small assistants anyone can build and publish inside ChatGPT. This one was called "Plus 5.6." It sat on chatgpt.com: real address, real padlock, real company. It told visitors the service was busy on the main site and sent them to a backup link. The backup link showed a "confirm you're human" box, the kind everyone clicks through a dozen times a week. This one asked for something slightly different: copy this line, paste it into Windows, press enter. The people who did that handed over the machine. Remote desktop, screen capture, browser control, and a foothold that survived a restart. For transparency: Huntress sells security monitoring to small businesses and to the IT firms that serve them, so the people who found this also sell the cure. Worth knowing who's asking the questions. Including ours. The technical part — you can skip this box Reported by Mark O'Halloran and Jonathan Semon at Huntress, published September 28, 2026. A malicious ChatGPT Custom GPT titled "Plus 5.6," promoted through sponsored Google search results for "chatgpt," served a fake "Service Availability Notice" claiming limited availability on the primary domain and redirecting to a Google Sites page. That page carried a ClickFix lure styled as a Cloudflare CAPTCHA check, instructing the visitor to copy a command and run it. The command was PowerShell, and referenced its download host in decimal notation — 1614733393, which resolves to 96.62.224.81 — retrieving an obfuscated script that silently installed an MSI package. The resulting eight-stage chain established dual persistence through a Run registry key and a scheduled task, sideloaded malicious DLLs using legitimately signed Canon and later Stardock executables, and concealed the final payload inside a custom encrypted file system. The payload is a remote access trojan with remote desktop, screen capture, browser control and follow-on payload capability. Huntress's security operations team investigated at least 40 incidents originating from the same Google Sites domain, two of which were confirmed to have begun at the Custom GPT. OpenAI removed it once reported; the attackers published a replacement and resubmitted it to Google's ad network. Huntress's detection guidance: PowerShell invoking msiexec against GUID-named MSI files in %TEMP%, signed applications running from imitation product folders under %LOCALAPPDATA%\Programs\, and persistence entries named "Canon Configuration Reader." What that actually means A "Custom GPT" is a small assistant any user can build and publish inside ChatGPT. Anyone can make one, and the listing lives on OpenAI's own domain. That is what made this work. "Paste this and press enter" is the entire attack. Nothing was exploited in ChatGPT, in Windows, or in the browser. A person was asked to run a program, and ran it. "Sponsored result" means they bought the top of the Google page. That's a line item, not a hack. The good news, and it's the larger half There is no drive-by version of this, and no silent version. Nobody gets caught by visiting a page. It requires a human being to copy an instruction and carry it out, which means one habit stops the whole family of attacks, and the habit fits in a single sentence. The part that doesn't help Twenty years of advice pointed at the address bar. Check the domain, look for the padlock. Here both were genuine, and the trap came one click later on a page that looked like the security check you've been trained to expect. The old rule still holds. It just stopped being enough on its own. What to do, and it takes one meeting Say the sentence out loud to everybody: nobody ever copies a command into Windows because a web page asked them to. Not to fix a slow connection, not to prove they're human, not to finish an update. There is no legitimate situation where a website needs that. Add the second half: a real service does not move to a backup link. Microsoft, Google and OpenAI do not run spare sites you get redirected to. That's the tell. Then say what happens next, because this is the part people get wrong. Anyone who pastes something and thinks better of it should say so immediately, not tidy it up. An hour of embarrassment is cheap. A week of quiet is not.