Cybercriminals are exploiting ChatGPT’s content-sharing feature to host fake outage notices that trick users into downloading malware by leveraging the trust associated with the legitimate chatgpt.com domain.
Key Points
- The "LLMShare" campaign uses Google ads to direct users to malicious shared ChatGPT pages that display fake service outage alerts.
- Attackers use custom HTML and CSS within shared conversations to mimic official OpenAI system messages.
- Users are prompted to download a fake desktop application from the site openew[.]app, which installs malware on Windows and macOS systems.
- The malicious download site employs cloaking techniques to display harmless content to security scanners while targeting actual users.
- Similar exploitation tactics have been observed targeting Anthropic’s Claude Artifacts and other AI platform sharing features.