TF-1932544
high
📛 Threat Title
Unknown malware: URL that delivers a malware payload https://openai-credits.com/
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 90. First seen: 2026-09-25 01:00:37 UTC. Reporter: CarsonWilliams. Tags: ClickFix.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
https://openai-credits.com/
UrlVoid 4 / 36
IOC database
- Type
- url
- Value
https://openai-credits.com/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that delivers a malware payload attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 90. First seen: 2026-09-25 01:00:37 UTC. Reporter: CarsonWilliams. Tags: ClickFix.
Remediations (10)
-
web:cybersecuritynews.com
ChatGPT shared links are used in ClickFix attacks, tricking Windows users into running PowerShell commands that download malware .
-
web:cybersecuritynews.com
A new malvertising campaign is using fake ChatGPT download sites in sponsored search results to deliver malware to Windows and macOS users.
-
web:evalian.co.uk
A fake ChatGPT download site is spreading malware through sponsored search results. See how it works & what defenders should look for.
-
web:labs.cloudsecurityalliance.org
Key Takeaways Over the summer of 2026, threat actors repeatedly turned the public-facing, user-generated-content features of major AI platforms into malware delivery infrastructure, abusing the inherent trust users place in domains such as claude.ai and chatgpt.com.
-
web:oecd.ai
Threat actors are abusing ChatGPT's content-sharing and code-rendering features to host convincing fake outage and download pages on legitimate OpenAI domains. Victims, lured by malicious ads, are tricked into downloading infostealer malware , bypassing security filters and leading to device compromise and credential theft.
-
web:securityarsenal.com
A sophisticated social engineering campaign has emerged where threat actors abuse ChatGPT's legitimate content-sharing feature to deliver malicious software. By creating public share links that render fake " OpenAI outage" pages, attackers deceive users into downloading malware disguised as the official ChatGPT desktop application.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.clearphish.ai
Threat actors are abusing ChatGPT share links to host fake OpenAI outage pages that trick users into downloading malware disguised as the ChatGPT desktop app. Learn how the LLMShare campaign works and how to stay protected.
-
web:www.techtimes.com
ChatGPT Share Links Deliver Malware From OpenAI Domain, Evading Corporate Web Filters Attackers buy Google ads for ChatGPT searches and serve infostealer malware from real chatgpt.com share pages.
-
web:www.trolleyesecurity.com
A malicious ad for "chatgpt" leads not to a fake site but to a real chatgpt.com share link, one that every URL reputation checker trusts. Researchers detail how the LLMShare campaign hides malware delivery behind ChatGPT and Claude's own domains.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.