Threat actors are exploiting ChatGPT's content-sharing feature (chatgpt.com/s/ links) to host fake OpenAI outage pages via Google Ads, tricking users into downloading malware disguised as the ChatGPT desktop app. The 'LLMShare' campaign, discovered by Push Security, renders a convincing outage notice through ChatGPT's own HTML rendering capabilities, making the attack appear to originate from a legitimate OpenAI domain. Victims who click the download button are redirected to a cloaked site that serves macOS and Windows malware, likely infostealers. Similar abuse has been observed on Claude Artifacts and Grok, indicating a broader trend of attackers weaponizing AI platform sharing features.
Table of contents
Related Articles:123 Impressions