Security researchers at Push Security have identified a campaign they call "LLMShare" in which attackers abuse ChatGPT’s shareable session and conversation feature to host and distribute fake outage pages that encourage users to download a fraudulent desktop app. The story was reported by Bleeping Computer.
How the campaign works:
- Attackers create a custom HTML page via ChatGPT’s sharing functionality and produce a shareable link. The content is technically served under the chatgpt.com domain.
- The fraudsters promote the share link using Google Ads, targeting users searching for ChatGPT. Clicking the ad appears to open ChatGPT, but actually loads the malicious shared page that notifies users of a supposed service outage.
- The fake page claims there is an issue with the web version while stating the desktop application still works, and it offers a download for that app.
The offered download is available for both Windows and macOS, and installing it results in a malware infection on the victim’s machine. The attackers’ ultimate motive is not yet known; Push Security’s findings indicate the distributed installer is malicious.
Why this technique is notable
What makes this campaign notable is that the malicious content is hosted through the legitimate chatgpt.com domain using ChatGPT’s own sharing feature, rather than being placed on an unrelated fake domain. That makes the pages more convincing because the browser address bar shows chatgpt.com.
Similar tactics have been observed before, but LLMShare specifically relies on creating and sharing content from within ChatGPT itself.
Recommended precautions
- Be cautious with sponsored search results in Google; there is no indication that OpenAI is currently using paid ads for the real ChatGPT in these cases.
- After clicking a search result or ad, check the browser address bar: if there is a long path or additional characters after https://chatgpt.com, remove the extra part after .com and press Enter before downloading anything.
- Avoid installing applications from untrusted or unexpected sources, especially those offered via sponsored search listings.
Push Security’s report and Bleeping Computer’s coverage highlight how combining shareable platform content with paid ads can be used for deception, and they underline the need for vigilance when following links and downloading software.



