Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit ChatGPT Links to Deploy Malware on Windows

Hackers Exploit ChatGPT Links to Deploy Malware on Windows

Posted on September 1, 2026 By CWS

Windows users are facing a new cyber threat as hackers leverage ChatGPT links to distribute malware. This campaign manipulates shared ChatGPT URLs, tricking users into executing malicious commands on their systems.

How the Attack Unfolds

Instead of compromising the ChatGPT platform, attackers embed misleading messages within shared ChatGPT conversations. Victims are urged to visit a backup site, claiming high traffic on the original page. This site presents a fake human-verification screen, instructing users to open Windows Run, paste a command, and press Enter.

This deceptive action initiates a PowerShell-based download outside the browser, identified by JOERverser analysts as a ClickFix operation. Crucially, the legitimate ChatGPT domain remains uncompromised, highlighting the danger of malicious user-controlled content.

Implications and Analysis

According to Joe Reverser’s report for Cyber Security News, this campaign can reveal sensitive information about a victim’s computer. The malware retrieves a concealed software bundle containing a NetSupport remote-control client, posing significant risks of unauthorized access and monitoring.

The attack begins with genuine ChatGPT sharing URLs, misleading users with an availability warning and a link to an unrelated site. This tactic exploits the credibility of well-known services without breaching their infrastructure. By pairing AI branding with ClickFix prompts, attackers guide users toward manual command execution.

Execution and Concealment Techniques

The landing page uses OpenAI-themed wording and Cloudflare-style verification to seem legitimate. A button copies a PowerShell command to the clipboard, leading users through familiar sequences to execute the command via Windows features.

This approach minimizes traditional phishing warnings by avoiding direct file downloads. Instead, the victim unknowingly initiates the attack through built-in Windows functionality, bypassing usual security alerts.

The hidden command fetches a remote script, collecting device and network data and sending it to a Telegram chat. The script conceals its activity by hiding the console window and using execution-policy bypass settings, adding further PowerShell stages.

Mitigation and Precautions

To avoid falling victim to such attacks, users should be cautious of websites requesting them to open system utilities like Run or PowerShell. It’s advisable to close such pages and inspect clipboard content before executing commands. Organizations should also block related infrastructure and investigate relevant hashes to prevent malicious activities.

Indicators of compromise include specific URLs, domains, and file names linked to this malware campaign. Security teams are advised to monitor these indicators actively and report suspicious activities promptly.

In conclusion, vigilance and proactive security measures are essential to combat the evolving strategies of cybercriminals leveraging trusted platforms like ChatGPT to propagate malware.

Cyber Security News Tags:ChatGPT, ClickFix, cyber threat, Cybersecurity, Hackers, Malware, NetSupport, Phishing, PowerShell, Windows

Post navigation

Previous Post: 21,000+ Microsoft Exchange Servers Vulnerable to Exploitation
Next Post: Anthropic Unveils Claude AI Models for Enhanced Research

Related Posts

Technical Details of SAP 0-Day Exploitation Script Used to Achieve RCE Disclosed Technical Details of SAP 0-Day Exploitation Script Used to Achieve RCE Disclosed Cyber Security News
Senate Investigates Cisco Over Zero-Day Firewall Vulnerabilities Senate Investigates Cisco Over Zero-Day Firewall Vulnerabilities Cyber Security News
GhostShell Malware Targets Ukrainian Drones Using mTLS and Telegram GhostShell Malware Targets Ukrainian Drones Using mTLS and Telegram Cyber Security News
Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code Cyber Security News
Magecart Hackers Exploit 100 Domains to Steal Card Data Magecart Hackers Exploit 100 Domains to Steal Card Data Cyber Security News
Critical Vulnerability in SonicWall Appliances Exposes Networks Critical Vulnerability in SonicWall Appliances Exposes Networks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark