Skip to content

Image: zdnet.com · rights & removal

Executive Summary

A new scam is circulating that exploits users searching for "ChatGPT" on Google. The scheme begins with sponsored links, which direct users not to the official ChatGPT domain but to custom, user-generated GPTs. These deceptive links present messages claiming service availability issues and prompt the user toward an upgrade or a backup domain link. A more malicious path involves clicking a subsequent link, which directs the user to a fake Cloudflare verification page, instructing them to run a command in Windows/PowerShell, which installs malware. Users are advised to avoid clicking sponsored links and to treat links from chatbots with extreme suspicion.

Facts Only

* A scam involves a sponsored Google link leading to a custom GPT offering information.
* The fake interaction mimics a "Service Availability Notice" regarding the primary domain.
* Some responses lead to a site hosted on Google Sites, not the actual ChatGPT domain.
* Following a specific link leads to a fake Cloudflare verification page.
* This page instructs users to paste and run a command in Windows/PowerShell.
* Running that command installs malware on the computer.
* A user attempted this process and received a response with a link leading to a scam.
* A separate attempt by an editor resulted in access to the normal ChatGPT site.
* Google deactivated some associated ad campaign accounts.

Full Take

The pattern observed involves leveraging established trust—the familiarity of the ChatGPT brand and Google search results—to bypass critical evaluation. The attack shifts from simple misinformation (the fake error message) to direct system compromise (running malware via shell commands). This progression demonstrates a calculated escalation designed to maximize immediate user action through manufactured urgency and false security signals. The use of layered deception, where the initial lure appears legitimate while the final action demands a technical step, exploits the cognitive habit of seeking resolution from familiar systems. The core vulnerability is the hesitation between accepting convenience and verifying execution, especially when authority figures (like Google or OpenAI) are either slow to react or have established policies that do not immediately address novel threats like malvertising in this context.
Patterns detected: ARC-0043 Motte-and-Bailey, ARC-0045 Feature-to-Function Mismatch, ARC-0072 Authority Game

From the original · ZDNet Security

ZDNET’s key takeaways - There’s a new scam involving ChatGPT. - The scam starts with a sponsored Google link. - The link leads to a custom GPT that gives malicious information. A new scam involving ChatGPT has emerged, and it might lead you to install malware on your computer if you’re not careful.
Read the full story at zdnet.com

Sentinel — Human

Confidence

The article reads like investigative reporting synthesized around specific technical incidents, displaying a mix of personal experience and sourced details rather than purely machine-generated content.

Signals Detected
low severity: Sentence length variance exhibits natural fluctuation; author uses direct, anecdotal reporting mixed with formal claims.
low severity: The text successfully weaves together a specific anecdote (personal experience) with broader security advice, demonstrating an understanding of the narrative arc.
low severity: Attribution to specific experts (Roman Oliinyk) and official bodies (Google spokesperson) provides grounding; the inclusion of internal commentary suggests human editorial oversight.
low severity: The claims are highly specific, referencing internal processes ('Plus 5.6'), specific legal actions (Ziff Davis lawsuit), and specific technical advice, which suggests grounded reporting rather than pure fabrication.
Human Indicators
Inclusion of a personal anecdote describing the user's direct experience ('I tried the process myself...') provides a distinct voice.
The structure flows from problem identification to mechanism explanation to mitigation steps, typical of investigative or explanatory journalism.
The integration of expert commentary and official responses anchors the claims in verifiable external sources.
This new ChatGPT scam tricks you into installing malware | Huntaegis