Scammers Planted a Fake “Plus 5.6” Right on ChatGPT.com and Infected PCs Through a Bogus CAPTCHA

Huntress researchers uncovered a malicious campaign in which attackers used a Custom GPT on the real ChatGPT.com domain to distribute a remote access trojan. The fake bot was called “Plus 5.6” and was designed so that users could mistake it for a new ChatGPT model.
What made the scheme especially convincing was that victims really did land on chatgpt.com, not on a lookalike phishing domain. In some of the cases investigated, users reached the malicious Custom GPT through a Google ad result for the query “chatgpt”.
The only noticeable clue on the page itself was a note that the GPT was created by a third-party community builder. Custom GPT is in fact a standard ChatGPT feature, but this particular bot was set up by the attackers.
The fake ChatGPT sent users to a bogus CAPTCHA
After any message, “Plus 5.6” displayed a notice claiming the main service had limited availability and suggested using a “backup domain.”
The link then took the user outside ChatGPT – to a Google Sites page disguised as a Cloudflare check.
There, a common ClickFix scheme was used. Instead of a normal CAPTCHA, the user was asked to open PowerShell themselves and paste in a suggested command.
That step is what triggered the infection. Simply opening ChatGPT.com or the Google Sites page was not enough to install the malware.
As the Huntress experts found, PowerShell downloaded an obfuscated script that installed a malicious MSI package and launched a multi-stage infection chain.
The attackers even used a legitimate signed Canon file for DLL sideloading – loading a malicious library through a trusted application.
The trojan gained near-total control of the computer
The final payload was a RAT that the researchers labeled @input.
The malware can launch remote desktop sessions and stream the screen, and access the webcam, microphone and system audio.
It also includes a file manager with search across the computer’s contents and the ability to quietly download additional EXE, DLL, MSI, PowerShell scripts and other files.
For persistence on Windows, two mechanisms were used at once – a startup entry and a scheduled task. They were regularly restored if the user or security software removed only one of the components.
Huntress investigated at least 40 related incidents
Huntress recorded at least 40 incidents tied to the campaign’s Google Sites domain.
At the same time, researchers were able to directly confirm that the infection began through the malicious Custom GPT in two cases. The remaining incidents were linked to the same infrastructure, but the initial entry channel could not always be determined.
Huntress reported the first “Plus 5.6” it found to OpenAI, and it was removed by September 25. By September 27, the experts had found another Custom GPT linked to the same campaign.
The scheme shows that a familiar domain by itself no longer guarantees that further instructions are safe. Any “CAPTCHA” or check that requires you to open PowerShell, Terminal or the Run window and manually paste in a command is especially dangerous – a legitimate web check never needs that.