ChatGPT share links abused to host fake outage pages to deliver malware
Threat actors are exploiting ChatGPT's content-sharing feature to host convincing fake outage pages designed to trick users into downloading malware. This 'LLMShare' campaign leverages Google ads and a legitimate OpenAI domain to deliver malicious downloads disguised as the ChatGPT desktop application. The tactic highlights the potential for AI-powered platforms to be abused for malicious purposes, particularly through deceptive user interface rendering.
The recent 'LLMShare' campaign, identified by Push Security, utilizes Google advertisements to direct users searching for ChatGPT to a malicious shared page hosted on chatgpt.com. Once a user clicks the ad, they are presented with a rendered webpage mimicking an OpenAI outage notice, urging them to download the desktop application. This deceptive tactic exploits ChatGPT's ability to render HTML content, allowing attackers to seamlessly integrate malicious downloads into a familiar interface. The fake outage page includes controls like 'Show code' and 'Remix with ChatGPT,' revealing the underlying custom HTML and CSS rendering.