Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Custom GPT Ads Lure Users into Running Malware via PowerShell Commands

A new scam uses sponsored Google ads that appear to lead to ChatGPT but actually redirect to a custom GPT that serves a fake Cloudflare page prompting a PowerShell command, installing malware. The technique underscores the importance of robust security‑awareness training and verifiable evidence of safe‑browsing compliance.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 zdnet.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
zdnet.com

Malicious Custom GPT Ads Lure Users into Installing Malware via PowerShell Commands

What Happened — A new scam uses sponsored Google ads that appear to lead to the official ChatGPT site. The ad redirects users to a custom GPT that always returns a “limited availability” notice with a link. Clicking the link opens a fake Cloudflare verification page that prompts the user to paste a PowerShell command, which installs malware on the machine.

Why It Matters for Trust & Control Assurance

  • Demonstrates how attackers exploit trusted brand domains to bypass user vigilance, a scenario continuous security‑awareness programs are built to detect and document.
  • Highlights the need for verifiable evidence that employees follow safe‑browsing policies and that phishing‑simulation results are tracked over time.
  • Aligns with the Security Awareness Training capability, which provides ongoing training, simulated phishing exercises, and audit‑ready logs of user responses.

Who Is Affected — Users of generative AI platforms (enterprise and consumer), SaaS providers integrating AI, and any organization whose staff regularly accesses cloud‑based AI tools.

Recommended Actions

  • Reinforce safe‑browsing policies: require direct navigation to chatgpt.com rather than search‑engine clicks.
  • Deploy phishing‑simulation campaigns that mimic this custom‑GPT scenario to test and improve user detection.
  • Capture and retain logs of suspicious link clicks and PowerShell command executions for audit readiness.

Technical Notes — The scam leverages a sponsored Google ad, a custom GPT hosted on a Google Sites domain, a fake Cloudflare challenge, and a PowerShell payload that drops typical Windows malware. No CVE is involved; the attack vector is social engineering via malicious advertising.

📰 Original Source
https://www.zdnet.com/innovation/chatgpt-scam-malware-trap/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →