Scammers Are Now Hosting Malware on chatgpt.com. Yes, the Real One.

The rise of Scammers Are Now Hosting Malware is reshaping how we think about technology and security. I’ve spent twenty years telling people to check the URL before they click anything. If it says google.com or microsoft.com, you’re probably fine. If it’s russian-bank-login-totally-real.xyz, you run.

That rule just died.

Security researchers at Push Security have uncovered a campaign they’re calling LLMShare, and it’s one of the craftiest things I’ve seen this year. Attackers are using ChatGPT’s own content sharing feature to host malicious pages. The URL starts with chatgpt.com. The padlock icon is there. The domain is legitimate. Everything looks right.

It’s completely fake.

How the Attack Works

Here’s the playbook. It’s simple, which is exactly why it works.

Someone searches Google for “ChatGPT.” They see a sponsored ad at the top of the results (attackers are running Google Ads campaigns targeting these keywords). They click it. Instead of landing on a normal ChatGPT page, they’re taken to a shared ChatGPT conversation, sitting on the real chatgpt.com domain.

The page shows what looks like a legitimate outage notice. “We’re experiencing high traffic right now,” it says. “Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.”

Sounds plausible. ChatGPT does go down. They do have a desktop app. What’s the harm?

The “download” button takes victims to a site called openew.app, which is dressed up to look exactly like OpenAI’s official download portal. From there you get a choice: Windows or Mac. Both versions contain malware. The Windows version checks if it’s running in a virtual machine or sandbox first (researchers call this cloaking), meaning antivirus scanners often see nothing wrong. If it’s a real computer, the payload executes.

Why This Matters More Than a Standard Phish

We’ve all seen fake login pages before. What makes LLMShare different is the domain. It’s not chatgpt-support.com or openai-download.net. It’s chatgpt.com. The real one. Verified certificate. Green padlock. The whole trust infrastructure that we’ve spent two decades building into browsers is now working against us.

The attackers exploited ChatGPT’s HTML rendering capability. They wrote a prompt that generates a custom HTML and CSS page, published it as a shared conversation, and got a legitimate chatgpt.com/s/ URL out of it. Push Security noted that if you look closely, you can actually see the “Show code” and “Remix with ChatGPT” buttons on the page. It’s literally just ChatGPT rendering a malicious webpage.

This isn’t a vulnerability in the traditional sense. OpenAI’s systems are working as designed. The attackers are simply using the feature more creatively than the designers imagined.

It’s Not Just ChatGPT

This is part of a broader trend. Earlier this year, attackers ran Google Ads directing Claude users to shared Claude conversations containing malicious installation instructions. Other campaigns abused shared ChatGPT and Grok conversations to run ClickFix attacks, tricking victims into pasting commands into their terminals that installed malware.

Claude’s Artifacts feature has been used the same way. Every AI platform with a content sharing feature is now a potential malware distribution vector. The platforms built these features for collaboration and sharing. Criminals saw a trusted domain with user-generated content and built a scam delivery network on top of it.

This is what happens when platforms move faster than their threat models. AI companies are shipping features at breakneck speed. The security implications of those features often get considered after the fact.

What You Should Actually Do

First, the obvious stuff. Only download ChatGPT from openai.com. If you’re ever on a page that looks like ChatGPT but is asking you to download something, check the actual URL carefully. If it says chatgpt.com/s/ followed by a random string, you’re looking at someone’s shared conversation, not an official page.

Second, and this is important for IT teams: update your security awareness training. The old “check the domain” advice is no longer sufficient when attackers can host content on the same domain as the legitimate service. Your staff need to understand that chatgpt.com can serve malicious content, just like drive.google.com or dropbox.com can.

Third, endpoint protection that detects VM and sandbox evasion is not optional anymore. The LLMShare malware specifically checks whether it’s being analyzed before executing. If your security tools can’t flag that behaviour, you’re flying blind.

Fourth, organisations should seriously consider blocking or monitoring shared AI conversation links in corporate environments. I know that sounds heavy-handed, but when the attack surface includes legitimate domains that your proxy and firewall inherently trust, you need compensating controls.

Trusting a domain is not the same as trusting everything on it. The browser doesn’t know the difference between OpenAI’s outage page and a criminal’s ChatGPT conversation. You have to.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Zuckerberg and Chan’s Biohub Pours $1.8 Billion Into AI That Simulates Human Cells

Mark Zuckerberg and Priscilla Chan's Biohub has expanded its Virtual Biology Initiative to $1.8 billion, backed by the US government, Google DeepMind, and Meta. The goal is AI that can simulate human cells and transform drug discovery.

The Free AI Tool That Just Hacked Seven Banks: The Skill Floor Has Disappeared

An open-source AI penetration testing tool called ARTEX was used to breach seven South Korean financial institutions and expose 68,000 customer records. The scary part is anyone can use it.

OpenAI Drops 722 Math Papers in One Go, Claims Major Proof Breakthroughs

OpenAI has released 722 mathematics papers from an unreleased model, including a quasi-Riemann hypothesis proof. The drop marks a turning point for AI-driven discovery.

Someone Built a Fake AI Ad Empire to Steal Your Login. And It Worked.

A human-operated phishing platform is impersonating ChatGPT, Gemini, Claude, Perplexity and Meta Muse with fake advertising portals that steal credentials and bypass MFA. Island researchers found hundreds of victims and the campaign is still running.

Reflection AI’s Beam Is the West’s Latest Answer to China’s Open-Weight Dominance

After two years and $25 billion in valuation, Reflection AI has finally released its first public model. Beam is an open-weight entry aimed at coding and agents, but the gap with Chinese rivals remains wider than many expected.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.