Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that trick users into downloading malware disguised as the official desktop application. The campaign, named 'LLMShare' by cybersecurity firm Push Security, uses malicious shared links hosted on chatgpt.com to mimic legitimate service disruptions.
The attack begins when users searching for ChatGPT online click on Google ads that lead to a legitimate ChatGPT shared page—specifically a link formatted as chatgpt.com/s/—that displays a fake outage notice instead of a normal chat conversation. The notice reads: "We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue." The quote appears on a user-generated page and is not an official OpenAI message.
Unlike traditional phishing pages hosted on attacker-controlled domains, this fake notice is rendered directly through ChatGPT’s own interface. Attackers created a custom HTML page using ChatGPT’s rendering capabilities and published it via the platform’s share feature. The page includes visible 'Show code' and 'Remix with ChatGPT' controls, confirming it originates from a user-generated prompt rather than OpenAI’s infrastructure.
Users who click the download button on the fake outage page are redirected to openew[.]app, a website impersonating OpenAI’s official desktop app download portal. This site employs cloaking techniques to serve different content based on the visitor: legitimate users see a malware download page, while automated security scanners like URLScan are shown a benign site mimicking an AR/VR company.
The openew[.]app website offers downloads for both macOS and Windows that install malware on victims’ devices. BleepingComputer’s analysis of the Windows version using Any.Run found the installer executes commands to detect whether it is running on a real machine or in a virtual environment—a common tactic used by malware to evade analysis. The exact payloads delivered by these downloads remain unclear, though prior campaigns abusing AI platform sharing features have distributed infostealers designed to harvest credentials and sensitive data.
forum Comments (0)
No comments yet. Be the first to comment.