A Fake ChatGPT Model Lived on OpenAI’s Own Site for Days, Installing a Trojan on Anyone Who Clicked

Hackers built a malicious custom GPT called "Plus 5.6" that redirected visitors to a fake CAPTCHA and tricked them into installing a remote access trojan. A replacement reappeared within two days of OpenAI taking…

Get a summary in:
Cybersecurity concept image representing a malware threat disguised as a chatbot
Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google
AA
Admin AlexWriter
MA
M.AliFact-Checker

Published: October 1, 2026 · Last updated: October 1, 2026

TL;DR: Hackers built a malicious custom GPT called “Plus 5.6” that redirected visitors to a fake CAPTCHA and tricked them into installing a remote access trojan, and a replacement reappeared within two days of OpenAI taking the first one down.

Cybersecurity concept image representing a malware threat disguised as a chatbot

Someone built a fake AI model, hosted it on chatgpt.com using OpenAI’s own custom GPT feature, and used it to install a trojan that hands attackers near-total control of a victim’s computer. Security firm Huntress says it’s tied to at least 40 separate incidents so far, all traced back to one malicious Google Sites domain.

The setup is a version of an attack pattern called ClickFix, dressed up to look official because it’s technically running on OpenAI’s real domain. A custom GPT named “Plus 5.6” directed users to what looked like a backup or alternate access point, hosted on Google Sites. That page displayed a fake Cloudflare CAPTCHA, the kind of “verify you’re human” prompt everyone’s trained to click through without thinking. Except this one instructed victims to copy a block of code and paste it into the Windows Run dialog, a classic ClickFix move that turns the victim into the one who executes the malware themselves.

What lands on the machine is a remote access trojan Huntress is calling “@input.” It’s not a smash-and-grab tool. It gives attackers screen viewing, remote device control, webcam and microphone activation, file search and document access, and the ability to quietly install more malware components on top. Communication back to the attacker is encrypted specifically to dodge detection.

The “@input” trojan appears to be “part of a well-maintained, professionally run framework,” according to Huntress researchers.

That’s a polite way of saying this wasn’t some teenager’s first malware kit, it’s a product someone is actively supporting. OpenAI shut down the original “Plus 5.6” custom GPT after it was flagged on September 25. A replacement showed up within two days. That turnaround is the part worth sitting with: custom GPTs are easy to spin up, easy to name convincingly, and apparently not getting caught fast enough before real damage happens.

This isn’t really a story about ChatGPT being unsafe to use normally. It’s a story about how trust in a familiar brand gets weaponized. Nobody expects malware to show up wearing OpenAI’s own domain. That’s precisely why it works, and why custom GPT abuse is likely to keep showing up as a vector as long as the barrier to publishing one stays this low.

The practical takeaway for anyone using ChatGPT’s custom GPT directory: treat any prompt to run code outside the browser, especially anything routed through a Windows Run dialog, as an instant red flag, no matter how official the page around it looks.

Related: AI Coding Agents Quietly Leaked 13,000 Screenshots From 343 Companies, and Nobody Told Them To and Gemini 4 Argon Is Google’s New Flagship, and It’s Not for You.

Bottom Line: The malware here isn’t clever because of the code, it’s clever because of the address bar. As long as anyone can publish a custom GPT under a convincing name, platform trust is the actual vulnerability, not the software.

Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest

Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google