Artificial Intelligence

Bad trick: Attackers use ChatGPT share links for malware

Trusted links, real domains – and still malware: Cybercriminals abuse ChatGPT share links to lure users into a perfidious download trap. Is this an underestimated danger or an easy-to-spot trick?

Functions of modern AI services are exploited

What seems like a harmless click on a well-known link can just as easily become a ticket to malware. Security researchers at Push Security are currently observing a new wave of attacks in which cybercriminals are specifically exploiting functions of modern AI services – especially the share links of chatbots such as ChatGPT. At the center is a campaign under is called “LLMShare”.. Attackers use a simple but effective trick, as security researchers have discovered. Specifically, ChatGPT share links are misused to embed manipulated content. To users, this looks like a normal shared conversation, including a familiar URL structure.

The path to the trap often begins with Google. The perpetrators use paid advertisements to place links to search terms such as “ChatGPT Download” or “ChatGPT Desktop App”. This is old hat; this scam has of course been known for a long time. Anyone who clicks on it will not end up on an obvious phishing page, but on a real domain with a seemingly trustworthy link. Classic protection mechanisms, such as web filters or firewalls, often do not work because the domain itself is considered reputable.

Tricky indication of high server load

A credible “disturbance” is then simulated on the site itself, for example through indications of high server load. Users will be prompted to download a desktop application to continue. However, the supposed download leads to an external site that looks very similar to official offers, but has nothing to do with the original site. Malware is ultimately distributed there, for both Windows and MacOS systems. The attackers can do this so easily because many users are not yet fully familiar with ChatGPT and its sharing functions. Technically, the attackers are becoming increasingly sophisticated. Computer crime infographic: Where cyberattacks originate When they start, the malware checks whether they are running in a real user environment or in an analysis environment. Security software and virtual test systems should be recognized and bypassed in this way. While various system checks are carried out under Windows, the MacOS version aims to read out sensitive data directly.

Caution is advised

This means one thing above all for users: a trusted link is no longer a guarantee of security. It’s worth taking a second look, especially when it comes to downloads from search ads or supposedly official sources – especially if unusual detours or additional installations are required.

View Comments

Share
Published by
Amit Gohar

Recent Posts

iOS and Android: Messenger WhatsApp brings its own backup alternative

WhatsApp is planning its own cloud storage for backups with mandatory end-to-end encryption. However, the…

4 hours ago

Firefox updates: Mozilla is drastically shortening the release cycle

Users of the Firefox web browser will soon receive updates twice as often. Starting in…

4 hours ago

Samsung Health forces users to share data with AI models

A new update to the Samsung Health app presents users with a tough choice. Anyone…

4 hours ago

Price slide continues: Elon Musk’s SpaceX is approaching the IPO price

After the recent IPO, SpaceX shares are plummeting. The price fell below $140 and is…

4 hours ago

Galaxy S26 Ultra: Samsung confirms red tint on flagship display

Users of the Galaxy S26 Ultra have been complaining about an annoying red tint on…

4 hours ago

Steam Machine too expensive? Valve is already naming the next problem

Buyers of the new Steam Machine will have to dig deep into their pockets, as…

4 hours ago