Fake ChatGPT Desktop App Ads Used to Push Password-Stealing Malware

https://hackread.com/wp-content/uploads/2026/06/fake-chatgpt-desktop-app-ads-password-stealer-malware-1024x576.jpg

Hackers are increasingly exploiting trusted artificial intelligence (AI) platforms like ChatGPT and Claude to turn them against their own users. Recently, Hackread.com reported a flaw called ClaudeBleed, discovered by LayerX, which allowed unauthorised browser extensions to hijack Anthropic Claude’s interface. Now, hackers are reportedly abusing official features of these AI tools to spread malware while easily evading web filters and security checks.


The Fake Outage Trick

These observations are strengthened by new research from security firm Push Security disclosing a campaign named LLMShare involving what researchers called InstallFix attacks.

“These are essentially InstallFix attacks — a variant of the ClickFix family…, and they exploit the fact that AI tools have normalized command-line installation workflows for a population of users who lack the experience to distinguish a legitimate terminal command from a malicious one,” researchers explained.

In this specific campaign, discovered on May 29, hackers purchased sponsored Google search adsfor...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE