Threat actors are abusing ChatGPT’s content-sharing feature to show fake OpenAI outage pages that trick users into downloading malware disguised as the ChatGPT desktop app.
The campaign, called “LLMShare” by Push Security, uses Google ads to target people searching for ChatGPT. When users click the sponsored ad, they are taken to a real ChatGPT shared page hosted on chatgpt.com, making the attack look more trustworthy because it appears on a legitimate OpenAI domain.
Instead of showing a normal shared conversation, the page displays a fake outage message claiming that the web version of ChatGPT is temporarily unavailable because of high traffic. The message then tells users to download the desktop app to continue using the service.
The fake notice says, “We’re experiencing high traffic right now,” followed by a message claiming the website is temporarily unavailable due to a large number of users. It then pushes visitors to download a desktop application.
What makes this campaign more unusual is that the fake outage page is not hosted on a traditional attacker-controlled phishing website. Instead, it is rendered through ChatGPT itself. The attackers created a custom HTML page using ChatGPT’s rendering features and published it through a shared chatgpt.com/s/ link.
Push Security said the page includes “Show code” and “Remix with ChatGPT” buttons, which reveal that the outage notice was generated from custom HTML and CSS inside a ChatGPT prompt.
When users click the download button, they are redirected to openew[.]app, a fake website designed to look like OpenAI’s desktop app download portal. Researchers found that the site uses cloaking, meaning it shows different content depending on who visits. Security scanners such as URLScan were shown a harmless AR/VR company website instead of the malicious download page.
The fake site offers both macOS and Windows downloads, which install malware on victims’ devices. Researchers have not yet confirmed the final payload, but similar campaigns abusing AI-sharing features have previously been used to deliver information-stealing malware.
BleepingComputer tested the Windows version in Any.Run and found that it runs several commands to check whether the device is a real computer or a virtual machine, a common behavior used by malware to avoid analysis.
Push Security also observed similar attacks abusing Claude Artifacts, Anthropic’s feature for sharing rendered apps and content. In those cases, attackers used ClickFix-style lures to trick users into running malicious commands.
AI platform sharing features have been abused before to spread malware. Earlier this year, attackers used Google ads to send users searching for Claude downloads to shared Claude conversations containing malicious installation instructions.
Other campaigns also abused shared ChatGPT and Grok conversations to carry out ClickFix attacks by pretending to offer software installation guides that told users to execute commands that installed malware.





