LLM Reveals New Hacking Attack: ChatGPT Sharing Page Used as Phishing Entry Point

As large language models gain widespread adoption, cybercriminals are refining their tactics, increasingly leveraging legitimate AI platform features to execute precise poisoning attacks. Push Security recently published a report detailing a novel threat dubbed "LLMShare," which exploits shared content mechanisms within large language models. By hosting malicious payloads directly on OpenAI’s official domain, attackers exploit user trust in established platforms to distribute malware.
This sophisticated campaign begins with attackers utilizing ChatGPT ’s content rendering capabilities to generate a custom HTML page within the official interface, which is then distributed via public "/s/" sharing links. Concurrently, attackers purchase premium ad placements on Google Search. Because these ads link to legitimate-looking URLs with official domains, both casual users and automated security scanners often fail to identify the threat during initial exposure.
Upon clicking the Google ad, users are redirected to a page that mimics a legitimate service but displays a deceptive "maintenance" notice. The page falsely claims the service is temporarily unavailable due to high traffic and urges users to "download the desktop application" to proceed.
Clicking the download button redirects victims to a malicious portal offering forged Windows and macOS client packages. These packages employ advanced evasion techniques: they present a benign, fake virtual reality company website to security scanners, while serving the actual malicious installer only to human visitors. Analysis reveals that these programs execute commands to detect virtual machine environments, delaying execution until they can operate undetected.
Security experts warn that this strategy, which relies on the perceived credibility of major tech companies, is gaining traction. Researchers have identified similar variants targeting the Claude platform, indicating that attackers are testing these social engineering scripts across multiple leading AI services. This exploitation of legitimate domain-sharing vulnerabilities highlights critical gaps in current internet security defenses.
Related article
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control
According to Business Insider, Google is testing Remy, a new AI personal agent for Gemini. This tool aims to execute tasks on behalf of users, streamlining both professional workflows and daily routines.Currently, Remy is undergoing testing in an int
Related Special Topic Recommendations
Comments (0)
0/500

As large language models gain widespread adoption, cybercriminals are refining their tactics, increasingly leveraging legitimate AI platform features to execute precise poisoning attacks. Push Security recently published a report detailing a novel threat dubbed "LLMShare," which exploits shared content mechanisms within large language models. By hosting malicious payloads directly on OpenAI’s official domain, attackers exploit user trust in established platforms to distribute malware.
This sophisticated campaign begins with attackers utilizing
Upon clicking the Google ad, users are redirected to a page that mimics a legitimate service but displays a deceptive "maintenance" notice. The page falsely claims the service is temporarily unavailable due to high traffic and urges users to "download the desktop application" to proceed.
Clicking the download button redirects victims to a malicious portal offering forged Windows and macOS client packages. These packages employ advanced evasion techniques: they present a benign, fake virtual reality company website to security scanners, while serving the actual malicious installer only to human visitors. Analysis reveals that these programs execute commands to detect virtual machine environments, delaying execution until they can operate undetected.
Security experts warn that this strategy, which relies on the perceived credibility of major tech companies, is gaining traction. Researchers have identified similar variants targeting the Claude platform, indicating that attackers are testing these social engineering scripts across multiple leading AI services. This exploitation of legitimate domain-sharing vulnerabilities highlights critical gaps in current internet security defenses.
U.S. Stocks Hit Historic Milestone as AI and Aerospace Giants Prepare for Trillion-Dollar Debut
Elon Musk, Sam Altman, and Dario Amodei, three titans of the technology sector, are advancing toward initial public offerings for their respective ventures. With SpaceX, OpenAI, and Anthropic—three industry behemoths nearing trillion-dollar valuation
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur





Home






