The address bar said chatgpt.com, and that was the entire trick
Every piece of advice about avoiding fake software starts with checking the address bar. Here the address bar was right. The page really was on chatgpt.com, because the attackers had built their lure inside OpenAI's own Custom GPT feature, which lets anyone publish a configured version of ChatGPT on the real domain.
Huntress published the teardown on 28 September. People searching Google for "chatgpt" hit a sponsored result that led to a Custom GPT named "Plus 5.6", chosen to read like an official model. Type anything into it and it replies that use on the main domain is restricted, offering a backup domain instead. The backup is a Google Sites page showing a counterfeit Cloudflare check, and the check asks you to paste a line into Windows PowerShell to prove you are human. Real Cloudflare has never asked anyone to do that.
What follows is long and deliberate. The command pulls down an obfuscated script, which installs an MSI, which drops a Canon-signed program next to a tampered DLL so Windows loads the bad one on the good one's reputation. The actual remote access tool is carried inside a file named Common.Integrator.Preview.wav. Once running it offers remote desktop, screen capture, camera and microphone, file searching, and the ability to fetch more. Huntress counted at least 40 incidents traced to that one Google Sites page. OpenAI removed the first Custom GPT on 25 September; researchers found a second one still up on the 27th. The feature is being retired on 11 December anyway.
The rule that survives all of this is narrow and worth memorising: no legitimate site, captcha or download page will ever ask you to copy something into PowerShell or the Run box. If you have already done it once, assume something ran. Tendvane's safety check goes through what is installed and what starts with Windows, which is where a thing like this eventually shows itself.