logo

Weaponized ChatGPT Download Site Delivers Malware Via Sponsored Search Results

ID: 12a40d01-7150-5a6f-abc7-3db59bbf0e58

STIX ID: report--12a40d01-7150-5a6f-abc7-3db59bbf0e58

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Abinaya

...
...

A malvertising campaign impersonating ChatGPT distributes trojanized Windows and macOS installers via sponsored search ads and an OpenAI-branded fake site; researchers identified the malicious domain (openew.*) resolving to 144.172.104.205 and provided SHA256 hashes for Windows and macOS samples. Analysis shows an Inno Setup installer deploying an Electron-based app with an obfuscated winter.js payload, use of PowerShell staging (ExecutionPolicy Unrestricted), CAPTCHA gating to evade sandboxes, DoH for blending C2 traffic, and persistence via a Chromium-style profile at %AppData%\Satoshi—defenders should monitor the provided IoCs, unexpected Electron applications, mismatched installer metadata and signatures, and the described process/network behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.