
Security Researchers Discover Fake ChatGPT Ads Tricking Users into Downloading Malware
- Tags
- Tech News
- Cybersecurity
- ChatGPT
- Artificial Intelligence
- Malware
- Google Ads
Introduction to the Threat
Security researchers from the artificial intelligence security company Island have uncovered a sophisticated and deceptive malvertising campaign targeting Windows users. The campaign utilizes sponsored Google ads promoting fake versions of ChatGPT to trick unsuspecting individuals into downloading dangerous malware. As AI tools like ChatGPT continue to dominate the digital landscape, threat actors are increasingly leveraging popular brand names to execute advanced cyberattacks.
How the Fake ChatGPT Ad Scam Works
The malicious scheme begins when users search for popular AI terms like 'ChatGPT' on Google Search. Sponsored ads appear at the top of the search results, masquerading as legitimate interfaces. According to Island's findings, these ads initially lead users to what appears to be a normal ChatGPT landing page.
However, once a user enters a prompt into the chat interface, the fake service purposefully triggers a redirection to a 'backup domain' under the guise of handling 'high traffic.' This backup domain directs victims to another fraudulent instance of ChatGPT featuring a fake Cloudflare verification page designed to initiate 'ClickFix' tactics.
The Mechanics of ClickFix Traps
ClickFix traps are engineered to manipulate users into executing malicious commands directly on their devices. In this campaign, the instructions on the fake backup page trick Windows users into copying and running commands via PowerShell or the Windows Run dialog.
Once executed, the underlying malware installs itself onto the host computer. The malicious payload is designed to persist even after system reboots, and it utilizes Telegram bots to exfiltrate stolen data back to the cybercriminals. Furthermore, the malware often deploys tools like NetSupport RAT (Remote Access Trojan), granting unauthorized remote control over the infected machine.
Scale and Scope of the Campaign
Telemetry data collected by researchers revealed that the campaign operated extensively between May and August 2026. During this three-month window, the threat actors deployed approximately 850 paid advertisements, 26 distinct fake ChatGPT links, and 71 unique Google Ads campaign IDs, highlighting the organized and persistent nature of the threat.
How to Protect Yourself from Malvertising
To avoid falling victim to these sophisticated online scams, users should implement the following precautionary measures:
- Go Direct: Always navigate directly to official domains like
chatgpt.comrather than clicking on sponsored search engine ads. - Use Ad Blockers: Employ reliable ad-blocking extensions to hide sponsored search results entirely.
- Ignore System Prompts: Legitimate website verifications, CAPTCHAs, or error messages will never ask you to open Windows Run, use PowerShell, or execute manual command-line scripts.
- Check Official Status Pages: If an AI service experiences downtime or heavy traffic, verify the outage via official status sites, such as OpenAI's official status page, instead of following prompts to alternative domains.
- Install Robust Antivirus Software: Ensure your computer is protected with up-to-date antivirus and anti-malware security suites.
Comments (0)
Sign in to join the conversation.Sign in
Loading comments...