ChatGPT share links abused to host fake outage pages to deliver malware
Threat actors used ChatGPT share links to show fake outage pages that pushed users toward malware disguised as the ChatGPT desktop app.
Intelligence analysis by GPT-5.4 Mini

The campaign, called LLMShare, leans on a legitimate chatgpt.com shared page to present a fake outage notice and route victims to a download site that impersonates OpenAI. Security researchers say the lure is paired with cloaking and likely malware payloads.
Some bad actors used a real ChatGPT sharing page like a disguise. The page looked like a service problem notice and said the app should be downloaded instead.
That is like putting a fake sign inside a real store and pointing people to a bad door. Because the page sits on a trusted site, it can seem safer than it really is.
The danger is that the download can install harmful software. Security teams now have to watch for tricks that hide inside trusted tools, not just fake websites.
Analysis
What happened
Threat actors are using ChatGPT’s content-sharing feature to host a fake OpenAI outage page on a legitimate chatgpt.com URL. The lure tells visitors that the web version is unavailable and pushes them to download a desktop app instead.
How the lure works
According to Push Security, the campaign uses Google ads to catch people searching for ChatGPT. Clicking the ad sends the user to a shared ChatGPT page, where custom HTML and CSS render the outage notice. The page also exposes controls such as “Show code” and “Remix with ChatGPT,” which helps confirm that the fake notice is being delivered through ChatGPT’s own rendering system rather than an attacker-owned site.
From there, the download button leads to openew[.]app, a site that imitates an OpenAI desktop download portal. The researchers say the site uses cloaking: security scanners such as URLScan were shown a harmless AR/VR company page instead of the malicious content.
Why it is concerning
The article says the site offers both macOS and Windows downloads that install malware, though the final payload is not fully identified in the report. BleepingComputer’s test of the Windows file on Any.Run showed behavior consistent with environment checking, including commands used to tell a real machine from a virtual machine.
The piece places this campaign in a broader pattern. Push Security has also seen attacks abusing Claude Artifacts and prior campaigns using shared ChatGPT or Grok conversations to deliver ClickFix-style lures and malware instructions. The main lesson is that trusted AI sharing features can be turned into delivery channels for phishing, fake installers, and malware, even when the visible URL belongs to a major platform.
Key points
- Attackers abused ChatGPT share links to host a fake outage page on a legitimate OpenAI domain.
- The campaign used Google ads to funnel searchers toward the malicious shared page.
- Clicking the fake download button sent victims to a site that impersonated OpenAI's desktop app portal.
- Researchers say the download site used cloaking to hide malicious content from security scanners.
- The report places the campaign in a wider trend of AI platform sharing features being used to spread malware.



