BotBeat
...
← Back

> ▌

OpenAIOpenAI
RESEARCHOpenAI2026-05-31

Attackers Using ChatGPT and Claude to Deliver Malware via Shared Pages

Key Takeaways

  • ▸Attackers exploit the inherent trust in ChatGPT.com and Claude.ai domains to bypass URL reputation security checks, hosting malware delivery pages on legitimate platforms
  • ▸The attack has evolved from simple terminal command sharing to sophisticated fake web pages using ChatGPT's code rendering feature, creating convincing mimics of legitimate service pages
  • ▸Both macOS and Windows users are targeted, with malware variants including infostealers like AMOS actively delivering threats via malvertising and SEO poisoning
Source:
Hacker Newshttps://pushsecurity.com/blog/llmshare-malvertising-campaign↗

Summary

Security researchers have uncovered an active malware campaign exploiting the shared conversation features of AI chatbot platforms, including ChatGPT and Claude. Attackers create malicious content on these trusted domains and drive traffic through malvertising and SEO poisoning, bypassing URL reputation checks. The latest variant uses ChatGPT's code rendering feature to create fake service disruption pages that redirect to malware downloads, evolving beyond earlier techniques that relied on social engineering with terminal commands.

This attack technique, identified as a variant of InstallFix attacks, exploits the normalization of command-line installation workflows among users unfamiliar with distinguishing legitimate from malicious commands. Shared Claude.ai conversations have been disguised as installation guides with fake Apple Support attribution, while parallel campaigns used ChatGPT conversations to deliver the AMOS infostealer. The current campaign remains active and generates ongoing detections, though users of affected security solutions are protected.

  • The technique exploits user unfamiliarity with terminal commands and the normalization of command-line workflows in AI tool adoption

Editorial Opinion

This attack reveals a critical vulnerability in AI platform architecture: features designed for legitimate knowledge-sharing become vectors for sophisticated social engineering. The fact that malware successfully routes through trusted domains like ChatGPT.com and Claude.ai underscores the urgent need for these platforms to enhance monitoring of user-generated content and implement stricter verification of shared pages.

Generative AICybersecurityPrivacy & DataMisinformation & Deepfakes

More from OpenAI

OpenAIOpenAI
INDUSTRY REPORT

The Paranoia Problem: How AI Writing Tools Are Making Real Writers Vulnerable to False Accusations

2026-05-31
OpenAIOpenAI
INDUSTRY REPORT

OpenAI Planning iPhone Rival as AI Agent Phone, Expected 2027 Launch

2026-05-30
OpenAIOpenAI
INDUSTRY REPORT

QEMU Relaxes AI Code Contribution Ban, Signaling Broader Industry Shift

2026-05-30

Comments

Suggested

AI Industry (Analysis)AI Industry (Analysis)
POLICY & REGULATION

Connecticut Enacts AI Transparency Law Requiring Employer Notification to Workers

2026-05-31
OpenAIOpenAI
INDUSTRY REPORT

The Paranoia Problem: How AI Writing Tools Are Making Real Writers Vulnerable to False Accusations

2026-05-31
Google / AlphabetGoogle / Alphabet
RESEARCH

Research Shows AI-Assisted Development Tool Gemini Does Not Substitute for Developer Expertise in Secure Coding

2026-05-31
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us