October 2, 2026
Fake ChatGPT Malware: How Custom GPTs Are Tricking People Into Running PowerShell
You open a page that looks like a custom ChatGPT.

By Ignatius Gigis
4 min read
It has the familiar layout. A chat box. A helpful-looking assistant. Maybe it promises to fix a browser problem, install an AI tool, or help you access a new service.
Then it tells you that something went wrong.
To prove you are human, it says, copy this command and paste it into PowerShell.
That is the moment the chatbot stops being helpful. It becomes the delivery mechanism.
The fake ChatGPT page looks useful
This is the latest version of an old trick: make the victim do the dangerous part themselves.
Researchers recently found a campaign sending people to pages hosted on Google Sites. The pages presented custom GPT-style experiences, then pushed visitors through a fake CAPTCHA. The "verification" step instructed them to open PowerShell and run a command.
According to reporting published by BleepingComputer on September 29, the campaign was connected to at least 40 incidents. Researchers found two custom GPT variants involved in the activity, and one was still active when the report was published.
The malware was not hidden inside a mysterious attachment. It was not relying on an exotic software vulnerability.
It was asking the person sitting at the keyboard to paste a command.
How fake ChatGPT malware works
The attack is usually called ClickFix because the page pretends that something needs fixing before the user can continue.
The page may claim that the browser failed a security check. It may say that an update is required. It may show a CAPTCHA-like box and provide instructions that look technical enough to be believable, but simple enough to follow.
The victim copies the command. They paste it into PowerShell or another system tool. They press Enter.
From there, the command downloads and runs the real payload. In the campaign described by BleepingComputer, the chain could install malware capable of stealing information from the computer.
The page does not need to bypass every security control. It only needs to convince the user that the command is part of the normal process.
That is why the use of a custom GPT matters.
People are learning to trust AI interfaces. They ask them to explain errors, translate confusing instructions, and help with tasks they do not understand. A fake AI assistant borrows that trust before asking for the one action a normal website should never require: running a command on the computer.
Why the trick still works
A CAPTCHA is supposed to prove that you are a person, not a machine.
ClickFix reverses the idea. It uses the language of security to persuade a person to behave like an installer.
The instructions often look more credible because they use familiar names. PowerShell sounds like something an administrator might use. A custom GPT feels connected to a platform people already know. Google Sites is a real service. The page may even use clean branding and polished wording.
None of those things make the instruction safe.
A legitimate CAPTCHA asks you to identify images, click a box, or complete a visual puzzle. It does not ask you to open a terminal. It does not ask you to disable protection. It does not ask you to paste code supplied by a webpage.
The command is the CAPTCHA.
The computer can see what the browser cannot
The useful defensive capability here is endpoint monitoring that records the chain of activity after the user clicks: a browser launching PowerShell, PowerShell starting an installer, an unfamiliar program creating persistence, or a new process attempting to access saved credentials. That visibility can allow a security team to stop the activity before the attacker gets a foothold, even when the user has already made the mistake.
This matters because browser protection alone is not enough. Once the user copies and runs the command, the attack is no longer just a webpage problem. It is an endpoint problem.
A good investigation does not only ask, "Did the user visit a malicious site?" It asks, "What happened immediately after they visited it?"
What would you check?
Would your team know that a CAPTCHA never needs PowerShell?
Would someone recognise that a browser update should come from the browser itself, not from a block of text on an unfamiliar page?
Would you know if PowerShell suddenly downloaded an installer? Would anyone see that the installer created a new scheduled task, service, or startup entry?
These are not questions for the security team alone. The first decision is usually made by someone who is trying to get work done and believes the page is helping them.
The answer cannot simply be "tell people not to click suspicious links." This page may not look suspicious. It may arrive through an advert, a search result, or a link shared by someone they trust. The dangerous part is the instruction that follows the click.
The rule is easier to remember:
If a webpage, chatbot, or CAPTCHA tells you to open PowerShell and paste a command, close the page.
Do not investigate the command. Do not run it to see what happens. Do not assume it is safe because the page looks like ChatGPT.
Fake ChatGPT malware is a trust problem
The most effective malware page may not look like malware at all.
It may look like an assistant. It may speak in calm, helpful sentences. It may tell you that one small action will fix the problem.
That is what makes custom GPT malware dangerous. The attacker is not only hiding the code. They are hiding the decision that matters: the moment a person gives a webpage permission to use the computer on their behalf.
Fake ChatGPT malware works because it turns trust into a button.
The safest CAPTCHA is the one that never asks you to use a terminal.