A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL -- used malvertising and SEO poisoning to push Windows visitors to a credential-stealing loader and Mac visitors to Odyssey Stealer (an AMOS/Atomic Stealer fork) that also swapped in trojanized Ledger and Trezor wallet apps.
Reviewed by the Social Engineering Examples team.
In May 2026, Malwarebytes Threat Intel identified openew[.]app, a fake website closely impersonating OpenAI's ChatGPT download page, complete with matching dark-theme branding and separate download buttons for Windows and macOS. Visitors who clicked the Windows button received Chat_GPT.exe, a trojanized Inno Setup installer wrapping an Electron shell that dropped files under %APPDATA%LeronApplication, launched EApp.exe, displayed a CAPTCHA challenge to gate/delay sandbox analysis, then spawned PowerShell fed via stdin (`-ExecutionPolicy Unrestricted -Command -`) to run credential-stealing malware while beaconing to a hardcoded C2 (188.137.246.189). Visitors who clicked the macOS button received ChatGpt.dmg, containing Odyssey Stealer, a fork of the well-known Atomic Stealer (AMOS) malware-as-a-service family. Odyssey used a fake macOS-style password prompt to phish the user's login password, then harvested the keychain, browser cookies/logins across 12 Chromium browsers plus Firefox/Waterfox, Telegram session data, and files from 16 cryptocurrency wallet directories. Distinctively, it then downloaded trojanized replacements for Ledger Live, Ledger Wallet, and Trezor Suite and attempted to swap out the victim's legitimate wallet apps for the attacker's versions (using sudo if the password was captured, or rm -rf otherwise). Traffic to the fake site was driven via malvertising/search ads, SEO poisoning on ChatGPT-related and typo-squatted search terms, YouTube spam, and links in AI-focused Discord/Telegram communities. Push Security separately published research (published 2026-05-29, one day after Malwarebytes) on a related, more novel technique it named "LLMShare": a Google Ads campaign directed victims to a genuine chatgpt.com/s/ shared-conversation URL where the attacker had prompted ChatGPT's own code-rendering feature to build a fully custom HTML/CSS page mimicking a ChatGPT "high traffic/service disruption" notice, AI-generated deceptive content rendered live on a legitimate, trusted OpenAI domain, which then redirected the victim to openew[.]app.
The domain openew[.]app cloned OpenAI's dark-themed ChatGPT download page, complete with OpenAI-style branding and marketing copy, and offered separate "official" download buttons for Windows and macOS, mirroring how legitimate cross-platform vendors ship installers, which made the dual-download setup feel authentic. Traffic was driven to the site via search ads and SEO poisoning on terms like "chatgpt," "chatgpt free," "chat gpt," and typo variants ("chatgo," "chatgot," "cvhatgpt"), plus YouTube spam comments and links shared in AI-focused Discord/Telegram communities. Push Security separately documented a more sophisticated redirect chain, dubbed "LLMShare": Google Ads malvertising sent victims to a genuine, attacker-created chatgpt.com/s/ shared-conversation URL where the attacker had used ChatGPT's own code-rendering ("Show code"/"Remix with ChatGPT") feature to author and render a fully custom HTML/CSS page mimicking a ChatGPT "high traffic/service disruption" notice, AI-generated deceptive content served live from a legitimate, trusted OpenAI domain, which bypassed URL-reputation and Safe Browsing checks before the victim ever reached openew[.]app. Because .app domains require HTTPS by registry policy, and because the LLMShare redirect step lived on a real chatgpt.com URL, victims saw a normal padlock icon with no certificate warning at either stage. Windows visitors downloaded Chat_GPT.exe, an Inno Setup installer wrapping an Electron app skeleton; on execution it dropped files under %APPDATA%LeronApplication, launched EApp.exe (the Electron shell), and displayed a CAPTCHA challenge to the victim, per Malwarebytes, used as an anti-sandbox/anti-automation gate to confirm a real human was running it before continuing, after which it spawned PowerShell with `-ExecutionPolicy Unrestricted -Command -`, feeding commands via stdin so they never touched disk for scanners to catch; the sample beaconed to 188.137.246.189 over a /laravel.php API endpoint (9 of 69 AV engines flagged it at analysis time). macOS visitors downloaded a disk image containing ChatGpt.dmg, delivering Odyssey Stealer, an AMOS (Atomic Stealer) fork available as malware-as-a-service. Odyssey ran an AppleScript chain that first silently tested a captured/blank password against macOS directory-service commands, then, if that failed, displayed a fake system-style prompt ("Please enter device password to continue") to phish the login password in cleartext. It then exfiltrated the macOS keychain, cookies/saved logins from 12 Chromium-based browsers plus Firefox and Waterfox, Telegram session data, and files from 16 cryptocurrency wallet directories (Ledger Live, Trezor Suite, Exodus, Electrum, Sparrow, etc.) plus Desktop/Documents files with extensions like .wallet, .seed, .key, and .kdbx, compressing everything into an archive sent to a hardcoded server.
The lure was a near-pixel-perfect clone of OpenAI's own dark-themed ChatGPT download page, reached via sponsored/SEO-poisoned search results for "ChatGPT download" and close typo variants, YouTube spam, and links dropped in AI-enthusiast Discord/Telegram servers, with one distribution path (Push Security's "LLMShare") abusing a real chatgpt.com/s/ shared-chat URL to display an AI-generated fake "service overloaded" notice, built by prompting ChatGPT's own code-rendering feature, before redirecting out to the clone site. The tell that should have stopped victims: ChatGPT does not require or officially distribute a third-party desktop installer from a random .app domain (the legitimate paths are chatgpt.com itself, native OpenAI apps, or the Microsoft Store); a "Show code"/"Remix with ChatGPT" toggle on a supposed system outage page is a giveaway that the page is user-generated content, not a real OpenAI status message; and mid-install, a generic-looking CAPTCHA gate followed by a macOS password prompt reading "Please enter device password to continue" is not how native macOS installer authentication looks.
Malwarebytes disclosed the campaign publicly on May 28, 2026, stating its products detect and block the malware, and Push Security published related independent research on the AI-generated redirect technique (LLMShare) on May 29, 2026. No confirmed victim count, breach scope, or aggregate financial loss was disclosed in the public reporting; the domain's takedown/registrar status and any law-enforcement action were not reported in the sourced material, and OpenAI had not issued a public statement on the abuse of its shared-conversation feature as of the cited reporting.
This case shows how attackers weaponize the hype around a specific, wildly popular AI product (ChatGPT) as bait, and how the pattern generalizes to any trending software: a convincing clone site, cheap malvertising/SEO placement, and a valid HTTPS certificate (even on a "trustworthy-looking" .app domain) can be enough to bypass a typical user's instinct to check for a green padlock. The Push Security-documented redirect adds a further twist: attackers can now use an AI chatbot's own content-rendering and sharing features to generate and host a convincing fake system notice on the chatbot's own trusted domain, meaning the AI product itself becomes an unwitting delivery platform for AI-authored deceptive content, not just the impersonation target, a distinction from purely non-AI brand-impersonation lures. It also illustrates an escalation beyond simple credential/data theft: the trojanized Ledger/Trezor wallet-replacement step turns a single infection into a persistent, ongoing cryptocurrency-theft mechanism that can silently intercept future legitimate wallet use, not just steal what's on disk at infection time. For a general audience, the key lesson is that "official-looking desktop app for [popular AI tool]" is an increasingly common lure precisely because so many users now expect AI products to have downloadable apps, and that even a page hosted on the real chatgpt.com domain is not automatically trustworthy content.
Malwarebytes states its products detect/block this malware. Practical defenses highlighted by the case: only download software from the vendor's official domain/app store (OpenAI's own chatgpt.com download page or the Microsoft Store) rather than search ads, unfamiliar results, or shared chatbot-conversation links; be suspicious of any "free desktop app" for a product that is primarily browser/mobile-based; note that a valid HTTPS padlock (including on trustworthy-sounding .app TLDs, and even a legitimate chatgpt.com URL itself) is not proof that the content on the page is genuine, since AI chatbot code-rendering/sharing features can be abused to host convincing fake system notices; treat any OS password prompt or CAPTCHA challenge that appears mid-install with suspicion, especially one styled generically rather than a native system dialog; verify that cryptocurrency wallet apps (Ledger Live, Ledger Wallet, Trezor Suite, etc.) were not silently reinstalled/replaced, and re-download wallet software directly from the hardware vendor if any compromise is suspected; enterprises can block/alert on PowerShell invoked with `-ExecutionPolicy Unrestricted -Command -` (stdin-fed scripting) and on the observed C2 indicator (188.137.246.189 /laravel.php endpoint).
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging…