logo

ChatGPT share links abused to host fake outage pages to deliver malware

ID: b9f8c8b7-ee57-5f07-8325-48ba225eae9c

STIX ID: report--b9f8c8b7-ee57-5f07-8325-48ba225eae9c

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Lawrence Abrams

...
...

Researchers discovered the "LLMShare" campaign where attackers use Google ads to send users to ChatGPT shared pages that render fake outage notices on legitimate chatgpt.com URLs; those pages instruct victims to download a desktop app from a malicious site (openew.app) that installs malware. The attackers leverage platform rendering, "Show code/Remix" features, cloaking to evade scanners, and previously observed techniques that distributed infostealers and ClickFix-style lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.