The images in this article were generated with artificial intelligence. How we publish
A campaign called "LLMShare" has shown to what extent attackers can take advantage of the public sharing functions of IA platforms to distribute malware convincingly: by using Google ads they directed users to shared ChatGPT links hosted on chatgpt.com that, instead of showing a conversation, gave up a false "outside" page and persuaded the victim to download an alleged desktop application that actually installed malware.
What makes this technique particularly dangerous is not only the bait of the sponsored announcement, but the use of legitimate resources from the platform itself to serve deception. In this case the attackers published HTML and CSS as shared content on chatgpt.com / s /, so that the malicious page was delivered from an official domain and showed controls such as "Show code" or "Remix with ChatGPT" which revealed that the content was technically a page generated by the tool itself.

The operators behind the campaign linked the download button to an impostor portal hosted in open [.] app that uses clapping techniques to show different content according to who the page requests: to analysis services they showed a harmless web, while to real victims they deployed the malicious installer. The samples analyzed by the researchers appear in VirusTotal and their execution in controlled environments showed typical behaviors of infostealers and checks to evade analysis within virtual machines (see analysis in Push Security and isolated tests in Any.Run).
This vector is not isolated: similar abuses against other IA platforms have already been documented, including Claude de Anthropic and old incidents with shared chats containing ClickFix-type malicious installation instructions. The novelty is pattern consolidation: legitimate ads on search engines → pages shared on IA platforms → redirection to false installers, which highlights a worrying trend in which confidence in official brands and domains is exploited as a front for malware.
The implications are broad. For users and organizations means that traditional signs of trust (official domain, corporate appearance, paid ad) are no longer security guarantees. For IA platforms there is an urgent need to review the capabilities of rendering and public sharing, establish controls for active HTML content and improve the mechanisms of moderation and scanning links. Advertising ecosystems must also tighten the verification of creative and campaign destinations to prevent legitimate ads from acting as a bridge to fraud.
If you want to reduce the immediate risk, apply practical measures: do not download applications from ads; always access official programs from the company's recognized channels (home page of the supplier or official application stores); before running an installer check the digital signature and hash of the file and compare it with official references or upload it to services such as VirusTotal; keep the security software and operating system up to date and, if you doubt, test the file in an isolated environment or virtual machine. More technical information on the samples detected is available in public reports, for example in BleepingComputer and on the VirusTotal analysis pages.
For corporate security teams the recommendations include blocking domains associated with the impostor site (such as openew.app in proxy and DNS filters), monitoring downloads and configuration changes in endpoints, enabling white list execution control for critical applications, and educating the template about the specific tactic (ad → shared link → false download). It is also prudent to implement the detection of connections to IA sharing services from workstations that should not use them and to require manual reviews when trying to run installers from untested sources.

For IA platform operators and advertising networks this campaign is a wake-up call: limit the ability to render active HTML in public content or add automatic and manual review processes for content that publish download links These are urgent steps. In addition, establishing clearer signals that distinguish official user-shared resources (verification marks, verifiable origins) and working with authorities and listing services for accelerated takedown requests would help to mitigate abuse.
The key lesson for any user is that the ease of sharing content that makes IA platforms valuable can also be used to effectively deceive. Keep skepticism to messages that request urgent downloads, confirm URL, verify signatures and hashes, and report suspicious links to the platform and security services. To further the technical analysis and follow-up of the case, consult the Push Security report on the campaign and follow-up articles in specialized media.
Recommended sources and readings: Push Security technical report on LLMShare ( https: / / pushsecurity.com / blog / llmshare-malvertising-campaign), media coverage in BleepingComputer ( https: / / www.bleepingcomputer.com) and the VirusTotal sample records for those who need to investigate commitment indicators ( Windows sample, sample macOS).
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...