Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malvertising Campaign Exploits ChatGPT for Malware Delivery

Malvertising Campaign Exploits ChatGPT for Malware Delivery

Posted on June 4, 2026 By CWS

A new wave of malicious advertising is exploiting the popularity of ChatGPT by promoting a counterfeit download site through sponsored search results, effectively distributing malware to both Windows and macOS platforms.

Deceptive Branding and Sponsored Ads

Security experts from Evalian’s SOC team have uncovered this operation, which utilizes authentic-looking OpenAI branding and search engine advertisements to attract users in search of legitimate AI tools. The core of the campaign is a malicious website, openew[.]app, which closely resembles an official ChatGPT download page.

On this site, users are offered various download options, including Windows, macOS, and a Chrome extension. While the browser extension redirects users to a legitimate listing, the Windows and macOS installers deploy trojanized payloads, compromising the user’s system.

Technical Analysis of the Malware

The domain, freshly registered via Namecheap, resolves to an IP address hosted on RouterHosting infrastructure, known for hosting short-lived malicious campaigns. The Windows payload, labeled as Chat_GPT.exe, utilizes an Inno Setup installer to deploy an Electron-based application. Despite its legitimate appearance, discrepancies in the binary’s metadata and code-signing certificate raise suspicions.

Further analysis reveals the application includes a Chromium-based runtime and an obfuscated JavaScript payload, complicating straightforward analysis. The program features Node.js modules that enable system reconnaissance, file manipulation, and command execution, indicating its malicious capabilities.

Evasion Techniques and Threat Landscape

The malware employs CAPTCHA-based gating to evade automated sandbox detection. Once the CAPTCHA is completed, multiple PowerShell processes are initiated, suggesting staged payload delivery through runtime command injection.

Evalian’s team notes the malware’s persistence through a Chromium-style profile in the %AppData%Satoshi directory, storing data such as cookies and cache files. The use of legitimate DNS-over-HTTPS services further obscures the malware’s command-and-control communications, blending them with normal network traffic.

The macOS variant remains largely undetected by antivirus software, indicating either a low distribution volume or effective evasion methods. This campaign exemplifies how threat actors leverage trusted branding and advanced application frameworks to refine their malvertising strategies.

Implications and Defensive Measures

This campaign underscores the evolving threat landscape as AI tools gain traction, highlighting the growing risk of brand impersonation in malware distribution. To combat such threats, defenders should monitor unexpected Electron applications, mismatched installer metadata, and unusual directories.

Proactive measures include analyzing process behavior and keeping an eye on newly registered domains masquerading as software vendors. As these threats persist, enhancing user awareness and implementing robust behavioral detection controls are crucial in safeguarding against these sophisticated attacks.

Cyber Security News Tags:ChatGPT, Cybersecurity, fake downloads, macOS malware, Malvertising, Malware, online safety, OpenAI, security threats, Windows malware

Post navigation

Previous Post: Offroad Secures $7M Funding to Address Identity Risks
Next Post: Willow Secures $7M to Enhance AI System Protection

Related Posts

FreePBX Servers Hacked in 0-day Attack FreePBX Servers Hacked in 0-day Attack Cyber Security News
Ivanti EPMM Exploited by Single IP with RCE Vulnerability Ivanti EPMM Exploited by Single IP with RCE Vulnerability Cyber Security News
Google to Flag Apps on Play Store that Use Excessive Amount of battery Google to Flag Apps on Play Store that Use Excessive Amount of battery Cyber Security News
MacOS Malware NimDoor Weaponizing Zoom SDK Update to Steal Keychain Credentials MacOS Malware NimDoor Weaponizing Zoom SDK Update to Steal Keychain Credentials Cyber Security News
Microsoft Defender AI to Uncover Plain Text Credentials Within Active Directory Microsoft Defender AI to Uncover Plain Text Credentials Within Active Directory Cyber Security News
AWS US-EAST-1 Region Experiences Delays in EC2 Instance Deployments AWS US-EAST-1 Region Experiences Delays in EC2 Instance Deployments Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark