ctipilot.ch

LLMShare malvertising via ChatGPT share links (Beagle infostealer)

campaign · item:llmshare-malvertising-chatgpt-share-links-infostealer-google

Coverage timeline
1
first 2026-05-30 → last 2026-05-30
Briefs
1
1 distinct
Sources cited
2
2 hosts
Sections touched
1
active_threats
Co-occurring entities
3
see Related entities below

Story timeline

  1. 2026-05-30CTI Daily Brief — 2026-05-30
    active_threatsPush Security; Google Ads + chatgpt.com share URL serving fake outage pages

Where this entity is cited

  • active_threats1

Source distribution

  • bleepingcomputer.com1 (50%)
  • pushsecurity.com1 (50%)

Related entities

Items in briefs about LLMShare malvertising via ChatGPT share links (Beagle infostealer) (1)

LLMShare malvertising campaign: attackers embed fake outage pages in ChatGPT share links and serve infostealer downloads via Google Ads

From CTI Daily Brief — 2026-05-30 · published 2026-05-30 · view item permalink →

Push Security documented LLMShare, a malvertising campaign in which attackers buy Google Ads targeting "ChatGPT" and "ChatGPT download" queries (Push Security, 2026-05-29; BleepingComputer, 2026-05-29). Victims clicking the ads land on legitimate chatgpt.com/s/[unique-id] share URLs that render attacker-controlled HTML — a fake high-traffic outage page with a "Download our desktop app to continue" button — directly from the OpenAI domain. Because chatgpt.com is trusted by enterprise web-filtering rules and firewalls, the landing page is not blocked. The download button redirects to an attacker-controlled domain impersonating OpenAI; the site uses cloaking (serves a benign page to scanners). Windows users receive an infostealer payload. The technique exploits the same ChatGPT Artifacts/sharing feature previously abused in the ACR Stealer campaign (covered 2026-05-26) and extends it to malvertising. Detection: monitor for browser-spawned executable downloads from chatgpt.com domains — legitimate ChatGPT desktop app downloads do not originate from that path; alert on unusual process launch from browser-extracted or browser-downloaded unsigned executables. MITRE ATT&CK: T1566.002, T1204.001, T1036, T1027.