All articles

Fake ChatGPT ads: how to spot a ClickFix malware trap

A fake verification can turn a search for ChatGPT into a malware risk. Learn which request should make you stop and what to do if you followed it.

October 11, 2026·4 min read·Posted in: Malware
DanishLæs på dansk
Share this article
X (Twitter)LinkedInFacebook
Fake ChatGPT ads: how to spot a ClickFix malware trap

A website asking you to run a Windows command to prove you're human is a reason to stop. Even if you arrived through a familiar service, that request puts your computer at risk.

In an October 1, 2026 report, Island traced Google ads through attacker-authored content on genuine ChatGPT pages. A fake service warning sent visitors to a supposed backup site, where a counterfeit verification asked them to run a Windows command that retrieved malware. The technique is called ClickFix.

Island recorded about 850 paid-ad landings across the broader cluster. Only a subset of destinations was confirmed to serve this exact lure. Those figures do not establish how many computers were infected.

A search result, a familiar chat interface and a security check can each feel routine. Together, they can make an unexpected instruction seem like the next step in getting work done.

The useful question is what the page wants you to do. Reading a response in your browser is one thing. Giving a command to your computer is a different action with different consequences. You don't need to understand the command to recognise that a human-verification check should never require it.

This is a practical addition to checking web addresses: assess the instruction as well as the page. A familiar name cannot make an unsafe request safe. Our guide to malvertising explains the wider problem of malicious advertising.

What ClickFix is asking you to do

Microsoft describes ClickFix as a technique that persuades people to execute malicious commands under the cover of a repair or verification. Instructions may mention Windows Run, Terminal or PowerShell, tools that can execute commands on your device. Delivered malware can include software that steals information or gives someone remote access.

Treat these requests as reasons to close the page:

  • Open a command window to complete a CAPTCHA or human check.
  • Paste text supplied by a webpage into a system tool.
  • Disable security protection to finish verification.

Don't try the steps to see whether they work. Ask your IT team through a contact method you already know.

If you saw the prompt or already followed it

If you only saw the prompt: close the page and avoid its backup or repair links. For work tools, return through your organisation's approved app launcher or a saved, verified bookmark. Report the suspicious page through your usual security channel.

If you pasted and ran a command: stop using the device for work and contact IT or security immediately, using another device if possible. Follow your organisation's incident procedure. Tell the team roughly when it happened, which page you visited and what actions you took. Don't run the command again to reproduce the problem.

If you aren't sure whether the command ran, say so. That uncertainty helps the team decide what to investigate. A window disappearing quickly is not enough to tell you whether the device is safe.

Give employees a clear place to stop

For organisations, a useful training exercise is to show a fake verification and ask where the employee would pause. Include the reporting route in the exercise so that asking for help is as straightforward as recognising the warning sign.

Microsoft recommends combining user education with device policies, such as restricting access to Windows Run where employees don't need it. IT should assess those restrictions against actual work requirements.

Make the everyday instruction simple: if a website asks you to run a command for verification, stop and contact IT. Employees shouldn't have to analyse a script before deciding they can ask for help.

Sarah Krarup

Sarah Krarup

Sarah studies innovation and entrepreneurship with a deep interest in IT and how cybersecurity impacts businesses and individuals. She has extensive experience in copywriting and is dedicated to making cybersecurity information accessible and engaging for everyone.

View all posts by Sarah Krarup
Get started

See how your team can reduce human risk

Explore how Moxso helps your team identify employee risk, target training and assess progress. Tell us where you want to reduce exposure.

  • Explore how training, simulations and follow-ups address gaps.
  • See how human risk varies across your organization, departments and employees.
  • Review how your goals automatically steer risk reduction.

By submitting this form, you agree to our Privacy Policy.

ISO 27001-certified ISMSReview the certificate and its scope.
EU sovereign by architectureData sovereignty compliance built in.