Hackers Abuse Real ChatGPT Links to Trick Windows Users Into Installing Malware
Brief
Windows users are being targeted through a malicious campaign that turns a ChatGPT shared link into the step of a malware infection.
Rather than breaking into the AI platform, the operators place a deceptive message inside a shared conversation and rely on victims to follow its instructions.
The page claims that traffic is too high and directs visitors to a supposed backup site. That destination uses a fake human-verification screen and tells people to open the Windows Run dialog, paste a command, and press Enter.
The action quietly starts a PowerShell-based download chain outside the browser. JOERverser analysts identified the activity as a malicious ClickFix operation, while stressing that the legitimate ChatGPT domain was not compromised.
