ChatGPT LLMShare Malware Campaign Abuses Share Links to Deliver Fake Outage Pages
Threat actors have launched a novel malware campaign dubbed LLMShare that abuses legitimate ChatGPT share links to deliver malicious payloads. The campaign uses ChatGPT’s own code-rendering feature to host fake outage pages on trusted OpenAI domains, bypassing traditional URL reputation checks and tricking users into downloading malware disguised as the ChatGPT desktop application.
What Happened: ChatGPT LLMShare Malware Campaign
On May 29, 2026, Push Security disclosed a sophisticated malvertising operation that leverages ChatGPT’s content-sharing capabilities as a malware delivery vector. Attackers purchase Google advertisements that target users searching for ChatGPT. Consequently, victims are redirected to legitimate chatgpt.com shared pages that display professionally rendered fake outage notices.
The fake page claims ChatGPT is experiencing high traffic and instructs visitors to download a “desktop app” to continue. However, the download button redirects users to attacker-controlled infrastructure at openew[.]app. Moreover, the downloaded executables install malware on both macOS and Windows systems.
This marks a significant evolution in malvertising tactics. Previous campaigns relied on attacker-controlled phishing domains. In contrast, the LLMShare campaign hosts malicious content directly on OpenAI’s trusted infrastructure, making detection far more difficult for traditional security tools.
Technical Details of the LLMShare Attack
The LLMShare campaign exploits ChatGPT’s ability to render custom HTML and CSS code within shared conversation links. Attackers create self-contained web pages using ChatGPT’s code output feature and publish them via chatgpt.com/s/ URLs. Therefore, the malicious content inherits the full trust reputation of OpenAI’s domain.
The fake outage page displays a convincing error message: “We’re experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.” The page includes a prominent download button and mimics OpenAI’s branding and design language.
Furthermore, the attackers employ sophisticated evasion techniques. The openew[.]app download site uses cloaking to display different content based on the visitor:
- Real users see a convincing clone of ChatGPT’s official desktop download page
- Automated scanners and security tools are redirected to a benign AR/VR company website
- This conditional rendering makes threat intelligence analysis significantly harder
Push Security researchers confirmed that the downloaded executables are flagged on VirusTotal. While the exact final payload remains under analysis, earlier campaigns using similar AI-platform sharing features have distributed well-known infostealers including Atomic macOS Stealer (AMOS).
In addition to ChatGPT share links, the attackers have also abused Claude Artifacts. Anthropic’s feature for sharing rendered applications and content has been used to host ClickFix-style lures that trick users into executing malicious terminal commands.
Business and Operational Impact
The LLMShare campaign poses serious risks to organizations and individual users alike. The abuse of trusted AI platforms creates significant challenges for security teams and end users.
- Credential theft: Infostealer payloads can extract passwords, session tokens, and cryptocurrency wallets from infected devices
- Corporate network compromise: Users downloading malware on work devices may expose internal systems and sensitive data
- Erosion of platform trust: AI platforms’ sharing features become potential attack surfaces, complicating safe usage policies
- Evasion of URL filtering: Traditional web gateways and email security tools typically allow traffic to chatgpt.com and claude.ai
- Cross-platform risk: Both macOS and Windows users are actively targeted, expanding the victim pool
Moreover, the campaign reflects a broader trend of attackers co-opting legitimate SaaS platforms for malware distribution. As AI tools gain widespread adoption, threat actors increasingly exploit their sharing and collaboration features to bypass security controls.
Mitigation and Recommendations
Immediate Actions for End Users
- Avoid downloading software from links embedded in AI chatbot shared pages or conversations
- Always navigate directly to official vendor websites for software downloads
- Verify executable signatures before installing applications
- Be skeptical of outage notices or urgent download prompts, even on trusted domains
Actions for Security Teams
- Update URL filtering policies to inspect shared AI platform links more closely
- Deploy endpoint detection rules targeting infostealer behaviors on macOS and Windows
- Educate users about the risks of AI platform sharing features and malvertising
- Monitor for downloads from suspicious domains such as openew[.]app and related infrastructure
- Review browser extension and execution policies to limit unauthorized software installations
Platform-Level Considerations
AI platform operators should implement additional safeguards for shared content. For example, rendering custom HTML within shared conversations could be restricted or subjected to additional scanning. Furthermore, user reports of abuse should trigger rapid content review and takedown workflows.
Bottom line: The LLMShare campaign demonstrates that trusted AI platforms are now viable attack surfaces. Organizations must update their threat models and user education programs to account for malware delivery via legitimate SaaS sharing features.
Incident Summary
| Incident Name: | LLMShare ChatGPT Malvertising Campaign |
| Disclosure Date: | May 29, 2026 |
| Discovered By: | Push Security |
| Affected Platforms: | ChatGPT (OpenAI), Claude (Anthropic) |
| Targeted Systems: | macOS and Windows desktops |
| Primary Vector: | Google Ads → ChatGPT shared pages → fake outage → malware download |
| Known Infrastructure: | openew[.]app |
| Patch Status: | N/A — mitigation and user awareness required |
References
- Push Security, “LLMShare: Using Shared Chatbot Pages to Distribute Malware,” May 29, 2026, https://pushsecurity.com/blog/llmshare-malvertising-campaign, accessed June 1, 2026
- Lawrence Abrams, BleepingComputer, “ChatGPT Share Links Abused to Host Fake Outage Pages to Deliver Malware,” May 29, 2026, https://www.bleepingcomputer.com/news/security/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware/, accessed June 1, 2026
- Kaspersky, “Shared ChatGPT Chats Used to Deliver AMOS Infostealer,” 2026, https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/, accessed June 1, 2026