Google Ads lead users to fraudulent ChatGPT Sites to install NetSupport RAT
Malicious Google Ads Pave the Way for NetSupport RAT
Cybersecurity researchers from Huntress and Island have uncovered a deceptive campaign targeting everyday users searching for ChatGPT on Google Search, where attackers purchased advertisements leading straight to fraudulent replicas designed to deploy remote access trojans. The operation exploits entirely legitimate infrastructure—including Google Ads, Google Sites, and official OpenAI domains—to deceive individuals seeking official software downloads, as gadget.ro reported.
The Trajectory of a Compromise
The attack begins the moment a user clicks on a top-ranking search engine ad that deceptively directs traffic to chatgpt.com. Upon arrival, visitors encounter a custom automated chat interface featuring a fictitious software release labeled “ChatGPT Plus 5.6.” The bot informs users that primary network servers are experiencing heavy traffic and supplies a hyperlink redirecting to an external site.
Social Engineering via PowerShell
The secondary portal demands human verification before granting access. When targets click the validation button, a background script copies an encoded script to the clipboard and instructs the user to paste and execute it via Windows PowerShell or the standard Run dialog. Executing the command triggers the silent installation of NetSupport RAT, a remote access trojan that grants operators real-time screen monitoring capabilities, webcam and microphone control, and access to stored credentials, financial data, and local files.

Bypassing Enterprise Filters
Security analysts note that modern cyberattacks increasingly use trusted enterprise services to bypass conventional security filters and user skepticism. By combining paid search advertising with legitimate domain redirection, the perpetrators lowered detection rates among casual web users. Investigators advise individuals to minimize reliance on third-party referral platforms and verify navigational targets directly to mitigate exposure to credential theft and persistent malware.