A fake ChatGPT model hosted on OpenAI's own domain was actually a doorway to malware.
Researchers at Huntress found a custom GPT called Plus 5.6 that displayed a single message no matter what you typed: a claim that chatgpt.com was experiencing limited availability and a prompt to visit a backup domain. That domain lived on Google Sites, a free website builder, and showed a fake Cloudflare CAPTCHA. Solving it meant copying a command into the Windows Run dialog, a classic ClickFix trick that gets victims to infect themselves. The payload was a remote access trojan Huntress calls @input, capable of taking over a victim's screen, webcam, microphone, and files.
This works because the custom GPT sits on the real chatgpt.com domain, so the usual advice to check the URL bar is useless. Huntress says the malware is part of a professionally maintained framework, and OpenAI's takedown of the first bot on September 25 did not stop a replacement from appearing two days later. At least 40 incidents trace back to just one of the Google Sites links involved.
ClickFix attacks have been spreading for a couple of years now, but routing one through a trusted AI platform's own domain is a reminder that verifying a URL is no longer the same as verifying what is actually running on it.