s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932544 high

📛 Threat Title

Unknown malware: URL that delivers a malware payload https://openai-credits.com/

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 90. First seen: 2026-09-25 01:00:37 UTC. Reporter: CarsonWilliams. Tags: ClickFix.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url https://openai-credits.com/ UrlVoid 4 / 36

IOC database

Type
url
Value
https://openai-credits.com/
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 90. First seen: 2026-09-25 01:00:37 UTC. Reporter: CarsonWilliams. Tags: ClickFix.

Remediations (10)

  • web:cybersecuritynews.com

    ChatGPT shared links are used in ClickFix attacks, tricking Windows users into running PowerShell commands that download malware .

  • web:cybersecuritynews.com

    A new malvertising campaign is using fake ChatGPT download sites in sponsored search results to deliver malware to Windows and macOS users.

  • web:evalian.co.uk

    A fake ChatGPT download site is spreading malware through sponsored search results. See how it works & what defenders should look for.

  • web:labs.cloudsecurityalliance.org

    Key Takeaways Over the summer of 2026, threat actors repeatedly turned the public-facing, user-generated-content features of major AI platforms into malware delivery infrastructure, abusing the inherent trust users place in domains such as claude.ai and chatgpt.com.

  • web:oecd.ai

    Threat actors are abusing ChatGPT's content-sharing and code-rendering features to host convincing fake outage and download pages on legitimate OpenAI domains. Victims, lured by malicious ads, are tricked into downloading infostealer malware , bypassing security filters and leading to device compromise and credential theft.

  • web:securityarsenal.com

    A sophisticated social engineering campaign has emerged where threat actors abuse ChatGPT's legitimate content-sharing feature to deliver malicious software. By creating public share links that render fake " OpenAI outage" pages, attackers deceive users into downloading malware disguised as the official ChatGPT desktop application.

  • web:urlhaus.abuse.ch

    URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...

  • web:www.clearphish.ai

    Threat actors are abusing ChatGPT share links to host fake OpenAI outage pages that trick users into downloading malware disguised as the ChatGPT desktop app. Learn how the LLMShare campaign works and how to stay protected.

  • web:www.techtimes.com

    ChatGPT Share Links Deliver Malware From OpenAI Domain, Evading Corporate Web Filters Attackers buy Google ads for ChatGPT searches and serve infostealer malware from real chatgpt.com share pages.

  • web:www.trolleyesecurity.com

    A malicious ad for "chatgpt" leads not to a fake site but to a real chatgpt.com share link, one that every URL reputation checker trusts. Researchers detail how the LLMShare campaign hides malware delivery behind ChatGPT and Claude's own domains.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.