
Malicious Custom GPTs on ChatGPT.com Lure Users into Installing Remote Access Trojans
A new scam uses sponsored Google ads to direct users to malicious Custom GPTs on the legitimate chatgpt.com domain. These fake interfaces display a 'Service Availability Notice' and link to a Google Sites page mimicking a Cloudflare check. The page instructs users to run PowerShell commands, installing a remote access trojan (RAT) via signed applications. Huntress confirmed at least 40 incidents, with OpenAI removing the first instance by September 25, 2026. Experts warn that trusted domains like ChatGPT and Google are being abused to bypass security awareness, urging users to never paste commands into terminals as a verification step.








