Hackers target ChatGPT and Claude shared features via Google Ads phishing

A new wave of phishing attacks targeting mainstream AI tools has been rising. Hackers are focusing on high-traffic AI services like ChatGPT and Claude, exploiting their official content sharing and plugin features to place nearly identical phishing links in top search engine ads. Since the root domain of these malicious landing pages exactly matches the official one, regular users find it extremely hard to spot them, significantly increasing the success rate of clicks and downloads of malicious installers.
In this exposed phishing method, hackers cleverly used ChatGPT Canvas's creation and sharing features to generate and share a highly realistic official-looking page under the official domain. Once users click through, a pop-up appears: "Traffic is too high — download the desktop client to continue." However, this misleading download button actually links to a pre-prepared malicious Trojan.
This deceptive method keeps succeeding because it expertly exploits user trust. First, the hackers generate and share content using ChatGPT.com's own canvas feature, so the resulting link carries an undeniable official domain. Second, the top ads they place on Google Search display a clean official domain URL, making users lower their guard before clicking. Finally, even when users land on the phishing page, the browser's address bar still shows ChatGPT.com unchanged, making it hard for mainstream security software to flag it as malicious.
Similarly, this attack method has also been observed on the Claude platform. Hackers use Claude.Ai's conversation sharing mechanism to pre-create malicious conversation records targeting various popular computer software (such as hardware diagnostic tools like CPU-Z). When users search for such software, the top fake ads direct them to Claude.Ai's official sharing link, then further trick them into downloading malware through deceptive text within the conversation.
As for this subtle attack method that relies on the implicit "endorsement" of major companies, industry experts acknowledge that because platform providers can hardly pre-review the vast amount of user-generated and shared content, such phishing activity is unlikely to be fully stopped in the near term and may even grow significantly. For everyday internet users, staying vigilant and avoiding downloading unknown "desktop clients" remains essential. Beyond that, installing reliable ad-blocking extensions in the browser to block top search engine promotional ads at the source may be the most effective self-defense against this kind of high-tech fraud at present.
Related article
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control
According to Business Insider, Google is testing Remy, a new AI personal agent for Gemini. This tool aims to execute tasks on behalf of users, streamlining both professional workflows and daily routines.Currently, Remy is undergoing testing in an int
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust
Related Special Topic Recommendations
Comments (0)
0/500

A new wave of phishing attacks targeting mainstream AI tools has been rising. Hackers are focusing on high-traffic AI services like
In this exposed phishing method, hackers cleverly used ChatGPT Canvas's creation and sharing features to generate and share a highly realistic official-looking page under the official domain. Once users click through, a pop-up appears: "Traffic is too high — download the desktop client to continue." However, this misleading download button actually links to a pre-prepared malicious Trojan.
This deceptive method keeps succeeding because it expertly exploits user trust. First, the hackers generate and share content using ChatGPT.com's own canvas feature, so the resulting link carries an undeniable official domain. Second, the top ads they place on Google Search display a clean official domain URL, making users lower their guard before clicking. Finally, even when users land on the phishing page, the browser's address bar still shows ChatGPT.com unchanged, making it hard for mainstream security software to flag it as malicious.
Similarly, this attack method has also been observed on the Claude platform. Hackers use Claude.Ai's conversation sharing mechanism to pre-create malicious conversation records targeting various popular computer software (such as hardware diagnostic tools like CPU-Z). When users search for such software, the top fake ads direct them to Claude.Ai's official sharing link, then further trick them into downloading malware through deceptive text within the conversation.
As for this subtle attack method that relies on the implicit "endorsement" of major companies, industry experts acknowledge that because platform providers can hardly pre-review the vast amount of user-generated and shared content, such phishing activity is unlikely to be fully stopped in the near term and may even grow significantly. For everyday internet users, staying vigilant and avoiding downloading unknown "desktop clients" remains essential. Beyond that, installing reliable ad-blocking extensions in the browser to block top search engine promotional ads at the source may be the most effective self-defense against this kind of high-tech fraud at present.
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust





Home






