MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-02 · via ZDNET

Fake ChatGPT Ads Lead Users to Malicious Custom AI Tool

Image via ZDNET
Image via ZDNET

Cybercriminals are running sponsored Google advertisements that mimic legitimate ChatGPT links but redirect users to fraudulent custom GPT versions designed to distribute malware. The scam appears authentic because users remain logged into their actual ChatGPT accounts and see convincing interface elements, making detection difficult. Users are advised to verify URLs carefully and be cautious when clicking on sponsored search results.

Expanded Detail

Cybercriminals are exploiting Google's paid advertising system to distribute malware through fraudulent ChatGPT replicas. The scam leverages custom GPT configurations—user-created AI tool variations—that display fake service notices claiming limited availability. The deception succeeds because victims remain authenticated to their legitimate OpenAI accounts while interacting with the malicious version, creating a veneer of authenticity that masks the threat.

The attack chain culminates when users click embedded links directing them to phishing pages featuring fake security verification screens. These pages instruct victims to execute commands in their system terminals, delivering malware payloads. Security researchers note that legitimate cloud infrastructure companies would never request command execution through such mechanisms, yet the sophisticated presentation may convince less technical users.

Context

This scam could significantly impact casual ChatGPT users who rely on search engines rather than direct URL access, potentially introducing malware across numerous compromised systems. Organizations and individuals may face data theft, system compromise, or credential harvesting if infected machines access sensitive information. The incident may accelerate adoption of browser security tools and heighten user skepticism toward sponsored search results. It could also prompt OpenAI and Google to implement stronger authentication safeguards and advertising verification protocols.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at ZDNET →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “This new ChatGPT scam tricks you into installing malware – how to spot the trap.” Browse more stories.