Urgent.News

What's breaking now, across thousands of outlets.

Tech

This new ChatGPT scam tricks you into installing malware – how to spot the trap

This authentic-looking scam starts with a sponsored Google link – and it’s catching people off-guard.

This new ChatGPT scam tricks you into installing malware – how to spot the trap

A new scam targeting ChatGPT users has recently emerged, aiming to trick individuals into installing malware on their computers. The scam begins when users search for "ChatGPT" online and click on a sponsored link that appears to be the actual website. Upon clicking, users are instead taken to a custom GPT, a user-generated ChatGPT version tailored for specific tasks.

The primary goal of this scam is to make users believe they are on the legitimate ChatGPT site, thus convincing them to click on a link inside the chat response.

The response presented by this custom GPT offers an upgrade to a Plus subscription or a link to a backup domain. Clicking on the provided link leads users to a fake Cloudflare verification page, which requests the user to paste and run a malicious command in Windows/PowerShell. Executing this command installs malware on the user's computer.

To avoid falling victim to this specific scam, users should recognize that a genuine Cloudflare verification check would never ask them to perform any actions on their keyboard. Instead, it might only require them to check a box or press a button. Additionally, users should treat sponsored results as advertisements and links from chatbots with caution, as they might not be trustworthy.

Tech professionals, such as Roman Oliinyk, CEO and founder of PayCore Media, Inc., an expert in data-leak protection systems for large US companies, have pointed out that real Cloudflare checks typically don't require any input from the user. Furthermore, Oliinyk recommends being wary of links from chatbots, as one should approach them with the same caution as links from a stranger.

Google and OpenAI were contacted for comments on this emerging scam; however, OpenAI has not yet responded.

Written by urgent.news from ZDNet's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at zdnet.com →

More in Tech

Bitbucket app passwords: move to API tokens

Key takeaways Pick the credential per consumer: an API token for a human, a repository access token for CI. A bot on someone's personal token dies when they leave.

  • Bitbucket urges users to move from app passwords to API tokens
  • App passwords will stop working on July 28, 2026
  • Three types of tokens: Atlassian, repository, and project access

More from Friday 2 October →