Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malvertising Campaign Exploits ChatGPT for Malware Delivery

Malvertising Campaign Exploits ChatGPT for Malware Delivery

Posted on June 4, 2026 By CWS

A new wave of malicious advertising is exploiting the popularity of ChatGPT by promoting a counterfeit download site through sponsored search results, effectively distributing malware to both Windows and macOS platforms.

Deceptive Branding and Sponsored Ads

Security experts from Evalian’s SOC team have uncovered this operation, which utilizes authentic-looking OpenAI branding and search engine advertisements to attract users in search of legitimate AI tools. The core of the campaign is a malicious website, openew[.]app, which closely resembles an official ChatGPT download page.

On this site, users are offered various download options, including Windows, macOS, and a Chrome extension. While the browser extension redirects users to a legitimate listing, the Windows and macOS installers deploy trojanized payloads, compromising the user’s system.

Technical Analysis of the Malware

The domain, freshly registered via Namecheap, resolves to an IP address hosted on RouterHosting infrastructure, known for hosting short-lived malicious campaigns. The Windows payload, labeled as Chat_GPT.exe, utilizes an Inno Setup installer to deploy an Electron-based application. Despite its legitimate appearance, discrepancies in the binary’s metadata and code-signing certificate raise suspicions.

Further analysis reveals the application includes a Chromium-based runtime and an obfuscated JavaScript payload, complicating straightforward analysis. The program features Node.js modules that enable system reconnaissance, file manipulation, and command execution, indicating its malicious capabilities.

Evasion Techniques and Threat Landscape

The malware employs CAPTCHA-based gating to evade automated sandbox detection. Once the CAPTCHA is completed, multiple PowerShell processes are initiated, suggesting staged payload delivery through runtime command injection.

Evalian’s team notes the malware’s persistence through a Chromium-style profile in the %AppData%Satoshi directory, storing data such as cookies and cache files. The use of legitimate DNS-over-HTTPS services further obscures the malware’s command-and-control communications, blending them with normal network traffic.

The macOS variant remains largely undetected by antivirus software, indicating either a low distribution volume or effective evasion methods. This campaign exemplifies how threat actors leverage trusted branding and advanced application frameworks to refine their malvertising strategies.

Implications and Defensive Measures

This campaign underscores the evolving threat landscape as AI tools gain traction, highlighting the growing risk of brand impersonation in malware distribution. To combat such threats, defenders should monitor unexpected Electron applications, mismatched installer metadata, and unusual directories.

Proactive measures include analyzing process behavior and keeping an eye on newly registered domains masquerading as software vendors. As these threats persist, enhancing user awareness and implementing robust behavioral detection controls are crucial in safeguarding against these sophisticated attacks.

Cyber Security News Tags:ChatGPT, Cybersecurity, fake downloads, macOS malware, Malvertising, Malware, online safety, OpenAI, security threats, Windows malware

Post navigation

Previous Post: Offroad Secures $7M Funding to Address Identity Risks
Next Post: Willow Secures $7M to Enhance AI System Protection

Related Posts

BioShocking Attack Exposes AI Browsers to Credential Leaks BioShocking Attack Exposes AI Browsers to Credential Leaks Cyber Security News
Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information Hackers Can Leverage Delivery Receipts on WhatsApp and Signal to Extract User Private Information Cyber Security News
Legacy WebBrowser Control Exploits Lead to RCE Legacy WebBrowser Control Exploits Lead to RCE Cyber Security News
New Report Claims Microsoft Used China-Based Engineers For SharePoint Support and Bug Fixing New Report Claims Microsoft Used China-Based Engineers For SharePoint Support and Bug Fixing Cyber Security News
AI-powered Pentesting Tool ‘Villager’ Combines Kali Linux Tools with DeepSeek AI for Automated Attacks AI-powered Pentesting Tool ‘Villager’ Combines Kali Linux Tools with DeepSeek AI for Automated Attacks Cyber Security News
Top Simulated DDoS Testing Tools for 2026 Top Simulated DDoS Testing Tools for 2026 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark