Warning: Sophisticated Fake ChatGPT Ads Are Spreading Malware to Windows Users

  • Tags
  • Cybersecurity
  • ChatGPT
  • Online Safety
  • Malware
  • ClickFix
  • phishing
  • Windows security

Security researchers have issued a stern warning regarding a dangerous new wave of cyberattacks targeting unsuspecting users searching for AI tools. According to findings from the security firm Island, malicious actors are leveraging sponsored advertisements on Google to distribute malware by masquerading as official ChatGPT services. These campaigns utilize a sophisticated technique known as 'ClickFix' to compromise Windows machines.

How the Scam Operates

The deceptive process begins when a user searches for 'ChatGPT' on Google. The search results feature sponsored ads that appear legitimate but actually direct users to fraudulent websites designed to mimic the authentic chatgpt.com domain. Once on these sites, the malicious interface attempts to create a sense of urgency. When a user enters a prompt, the site claims it is experiencing high traffic and provides a link to a 'backup domain.'

The 'ClickFix' Trap

Clicking the link to the so-called backup site initiates the infection process. The attacker presents a fake Cloudflare verification page. These pages include specific 'ClickFix' instructions, which urge the user to execute commands through the Windows 'Run' dialog or PowerShell. By following these malicious instructions, users inadvertently authorize the installation of malware.

Once the system is infected, the attackers employ tools like the NetSupport RAT (Remote Access Trojan), which grants them unauthorized remote control over the victim's computer. The malware is designed for persistence, meaning it remains active even after a system reboot, and utilizes bots on the messaging platform Telegram to exfiltrate stolen data back to the cybercriminals.

A Sustained Campaign

Data gathered between May and August 2026 indicates the scale of this operation, which involved approximately 850 paid advertisements, 26 distinct fake ChatGPT links, and 71 separate Google Ads campaign IDs. The attackers have shown a high degree of adaptability, continuously rotating domains and forms to evade detection.

How to Protect Yourself

Security experts emphasize that users must remain vigilant when interacting with sponsored search results. Key takeaways for staying safe include:

  • Verify the URL: Only access ChatGPT via the official 'chatgpt.com' domain. Avoid clicking on links from search ads if you are unsure.
  • Ignore Suspicious Instructions: No legitimate website verification (like a CAPTCHA or Cloudflare check) will ever require you to use the Windows Run command or paste code into PowerShell.
  • Check Official Status Pages: If you believe a service is down, always check the company's official status page (e.g., status.openai.com) rather than trusting a link provided by a random website.
  • Use Defensive Tools: Employ robust ad-blockers, which can often hide malicious sponsored links, and ensure you have up-to-date, reputable antivirus software installed on all your devices.

Comments (0)

Sign in to join the conversation.Sign in

Loading comments...