Affected Systems

OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT desktop application.

Exploitation Status

Active campaign in progress. Threat actors are actively exploiting ChatGPT's content-sharing functionality to host malicious pages on legitimate OpenAI infrastructure, lending credibility to the phishing attack. No CVE assigned as this is abuse of intended functionality rather than a technical vulnerability.

Business Impact

Users who fall for the fake outage pages may download and execute malware disguised as the ChatGPT desktop client. This poses risk of credential theft, data exfiltration, or initial access to corporate networks if employees use personal ChatGPT accounts on work devices. The abuse of legitimate OpenAI domains (chatgpt.com) makes traditional URL-based filtering ineffective and increases user trust in the malicious content.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Alert users via security awareness channels about fake ChatGPT outage pages and malicious desktop app downloads hosted on chatgpt.com shared links
  • Review web proxy and DNS logs for chatgpt.com/share/* URLs followed by executable downloads, particularly .exe, .msi, or .dmg files
  • Block execution of ChatGPT desktop installers from non-official sources; verify legitimate downloads only from openai.com/chatgpt/download
  • Implement application control policies to prevent unauthorized ChatGPT desktop client installations on managed endpoints
  • Monitor endpoint detection tools for suspicious processes masquerading as ChatGPT or OpenAI-related executables