logo

LLMShare campaign exploits ChatGPT to deliver malware

ID: 00bd8fd0-0a87-57c0-a60d-20682df5dc20

STIX ID: report--00bd8fd0-0a87-57c0-a60d-20682df5dc20

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-07-19

...
...

The LLMShare campaign used paid Google Ads for ChatGPT-related queries to link to legitimate chatgpt.com shared conversation URLs that displayed fake outage pages and directed users to openew.app for malicious downloads; the distributed Windows and macOS installers were identified as infostealer malware (Odyssey Stealer). The report details cloaking/evasion measures that showed benign content to scanners, observed detections by vendors, and recommends Zero Trust controls (allowlisting, ringfencing, web content control, and privileged access management) to mitigate this delivery technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.