The malicious GPT sat on chatgpt.com, the ad was bought on Google, and the victim pasted the command themselves
2026-10-01AI
Huntress traced a remote access trojan back to a Custom GPT called Plus 5.6, hosted on OpenAI's own domain and reached through a sponsored Google result for the word chatgpt. The page it sent people to imitated a Cloudflare check and asked them to paste a line into PowerShell. OpenAI removed the GPT on 25 September; a replacement appeared on the 27th.