Wire Observer.
Technology

Malicious Campaign Hijacks ChatGPT Share Links to Deploy Windows Malware

Malicious Campaign Hijacks ChatGPT Share Links to Deploy Windows Malware

Cybersecurity researchers have identified a new phishing scheme that leverages legitimate ChatGPT conversation links to distribute malicious software to Windows computers. The attack does not exploit any vulnerability in the AI service itself; instead, threat actors embed a deceptive instruction within a shared chat, prompting unsuspecting users to download and execute a payload.

In the typical scenario, a victim receives a URL to a ChatGPT conversation—often via email, social media, or messaging platforms—purportedly containing useful information. Within the chat, the attacker adds a message that appears to be a helpful tip or a necessary follow‑up, accompanied by a link to a file or installer. When the user clicks the link, the file downloads and, if run, installs malware that can steal credentials, encrypt files, or provide remote access.

The campaign specifically targets Windows users, taking advantage of the operating system’s large market share and the common practice of downloading executables from the web. Analysts note that the malicious links are often disguised with familiar domain names or shortened URLs, making the deception harder to spot. Because the initial ChatGPT link is genuine, many security filters do not flag it, allowing the malicious content to slip past traditional defenses.

Security experts stress that the attack vector is a classic example of social engineering: rather than compromising the AI platform, the perpetrators rely on human error. By embedding the lure inside a conversation that appears to be generated by ChatGPT—a tool many trust for accurate and helpful responses—the attackers increase the likelihood that recipients will follow the instructions without suspicion.

Microsoft and OpenAI have not reported any breach of the ChatGPT service itself. Both companies advise users to treat any external links shared in AI conversations with the same caution as links received from unknown sources. Recommended safeguards include verifying the source of the link, scanning downloads with up‑to‑date antivirus software, and avoiding the execution of files from untrusted origins.

Researchers continue to monitor the campaign’s evolution, noting that the tactics could be adapted to other platforms that support link sharing. Users are urged to stay vigilant, especially when receiving unsolicited ChatGPT conversation links, and to report suspicious activity to their IT security teams or relevant authorities.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related