Beware of Fake ChatGPT "Plus 5.6" | Infection via the Official Website
機械翻訳 / Machine-translated

機械翻訳 / Machine-translated
@aifriends
AI Friends(https://aifriends.jp)のクロスポスト公式アカウント。AIツールの紹介・使い方・できることを、中学生でもわかるやさしい日本語で届けます。
Do you think "if the URL says chatgpt.com, it must be real — so it's safe"?
An attack that exploited exactly that assumption was discovered in September 2026. This article explains, in plain language, how the fake ChatGPT "Plus 5.6" scheme worked and what you can do to avoid being fooled.
On September 28, 2026, U.S. security firm Huntress published an investigation report on a particular attack.
What the attackers exploited was ChatGPT's custom GPT feature — a function that lets anyone create and publish their own personalized ChatGPT.
They didn't build a fake website. They planted a trap inside OpenAI's official website.
The custom GPT in question was named "Plus 5.6."
It looked every bit like a new ChatGPT model or a paid plan upgrade. But no such product exists.
In reality, it was a GPT built solely to redirect visitors to a malware distribution page.
Huntress's monitoring team reported handling at least 40 cases connected to the same attack page.
Of those, only 2 were confirmed to have used the fake GPT as the entry point. The rest are believed to have been directed to the same page through other routes.
The targets were Windows PCs. The victims' countries, industries, and the attackers' identities have not been disclosed.
The attack unfolded in eight stages. Here, we walk through the parts visible to the user, in order.
It started with a Google search. When users searched "chatgpt," a sponsored ad appeared above the regular search results.
The ad's link led to the real chatgpt.com. The more careful a person was about checking the URL, the more likely they were to click confidently.
The page that opened was the fake GPT "Plus 5.6." No matter what the user typed, the same message came back.
The message was framed as a "service availability notice," claiming that usage was restricted on the main domain and asking users to either upgrade to Plus or continue on a "backup domain."
Since ChatGPT itself was delivering the message within the ChatGPT interface, it looked like an official announcement.
The link in the notice led to a page built with Google Sites (Google's free website creation service).
There, users saw a screen that looked exactly like a Cloudflare (a widely used web security service) "I am not a robot" verification page.
They were then instructed: "To verify, please copy and run this command."
This is the technique known as ClickFix — it gets users to execute malicious instructions with their own hands.
Running the command silently triggered an installer in the background.
What was exploited here was a legitimate program bearing Canon's digital signature — a certificate proving it came from a genuine manufacturer.
By loading malicious components through a legitimate program, the attack slips past security software. The final payload was a RAT (Remote Access Trojan — a virus that lets attackers freely control your computer from anywhere).
According to Huntress's analysis, this RAT had the following capabilities:
Imagine a freelancer working from home. Online meetings with clients, information saved in their browser — all of it exposed to an unknown stranger.
On top of that, the malware included two layers of persistence mechanisms to keep running after a restart, making it hard to remove.
What makes this attack so insidious is that every brand involved is real.
Huntress noted that "every stage of the attack borrows from brands that people already trust."
Consider this from the perspective of an IT administrator at a company. Domains like chatgpt.com and google.com are naturally allowed for business use.
That means tools designed to block suspicious sites wouldn't have stopped this attack's entry point at all.
After Huntress reported it, OpenAI removed the first fake GPT by September 25.
But just two days later, on September 27, a second fake GPT with the same name was discovered. At the time the report was published, it was still active.
The second version also made small changes to the method — using a different legitimate program instead of Canon's. The attackers clearly had a system in place to quickly rebuild once taken down.
In fact, this is not the first time attackers have used official AI service websites as a launchpad. It has been happening since late 2025.
| Period | Service Exploited | Entry Point | Malware Delivered |
|---|---|---|---|
| Late 2025 | ChatGPT & Grok shared chats | Search results & ads | Mac info-stealer "AMOS" |
| July 2026 | Claude artifacts (FakeAgent) | Bing search ads | SectopRAT |
| September 2026 | ChatGPT custom GPT (this case) | Google search ads | Custom RAT |
In July's "FakeAgent" attack, a fake app was distributed from a page on Claude's official domain. At least 29 organizations were reported to have been affected within two days.
Traditional ClickFix attacks took place on compromised or fake websites — where checking the URL could still tip you off.
In this new wave, the entry-point URL is genuine. Relying solely on "check the URL" is no longer enough.
You might think this is someone else's problem overseas. But Japan is actually one of the most targeted countries.
According to a report by security firm ESET, ClickFix detections from December 2025 to May 2026 increased by 108% compared to the previous six months.
By country, Japan ranked first at 14%. Japan's National Police Agency also issued a ClickFix advisory in October 2025.
The fake GPT in this case was in English, but changing a custom GPT's text to Japanese is trivial.
For example: a high school student rushing to meet a report deadline searches "chatgpt" and clicks the top link. If a message in Japanese says "Usage is restricted — please continue on the backup site," they might follow along without a second thought.
As a note, the custom GPT feature itself is scheduled to be discontinued on December 11, 2026. For more details, see our article on the custom GPT shutdown.
However, the same tactics could still be used during the roughly two months remaining. And after the feature ends, similar attacks targeting successor features or other AI services remain a real possibility.
No technical expertise required. Here are the key points to remember:
Huntress also emphasizes: "Legitimate websites will never ask you to copy and paste a command as proof that you're human."
Consider a company with around 30 employees. If everyone uses ChatGPT, it only takes one person clicking an ad to create an entry point into the organization.
If someone has already run the command, disconnect from the network immediately and consult your IT team or a professional. Also change your passwords from a separate device.
A. No. Simply opening the fake GPT does not cause infection. Infection occurs when you paste and run the command yourself on the fake verification screen you're directed to.
A. The confirmed attack in this case targeted Windows. However, similar techniques targeting Macs have been reported in the past. Regardless of your device, the rule is: don't paste commands.
A. No. It's a fake name invented by the attackers, designed to look like a real model or paid plan.
A. It's a technique that displays a fake error or verification screen to trick users into running a malicious command themselves. Because the user performs the action manually, it tends to bypass security measures.
A. There's no need to avoid GPTs from trustworthy creators. However, be cautious with GPTs opened via ads, or any GPT that directs you to an external site.
Start today by making it a habit to open ChatGPT through the official app or a bookmark.
This article is a cross-post from AI Friends.