TL;DR: Attackers are abusing shared ChatGPT and Claude content, plus sponsored malvertising and SEO poisoning, to deliver malware from pages hosted on trusted domains and to evade URL reputation checks before victims reach the payload, according to Push Security. The pattern shows that platform trust, not just malicious infrastructure, is now part of the attack surface.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms”.
Key questions
Q: How should security teams defend against malware delivered through trusted AI chatbot pages?
A: Security teams should treat shared AI content as a delivery channel and inspect the full page behaviour, not just the domain.
Q: Why do trusted chatbot domains make malware delivery harder to block?
A: Trusted chatbot domains complicate blocking because reputation systems, safe-browsing services, and user judgment all start from the assumption that the host is legitimate.
A: Common signs include unusually polished phishing language, rapid variation in tone, references to urgency or authority, and outputs that resemble social engineering templates rather than normal business writing.
Practitioner guidance
- Harden browser controls for trusted AI domains Inspect shared chatbot pages, redirects, and rendered content with browser-layer telemetry and policy enforcement.
- Monitor search exposure for AI brand terms Track sponsored results, typo variants, and poisoned search rankings for ChatGPT, Claude, and related AI tool terms.
- Block command-paste installation prompts Flag pages that instruct users to paste terminal commands or download desktop apps from a shared content URL.
Bottom line: Trusted AI chatbot pages can be turned into malware delivery steps when attackers combine shared content abuse with search-driven lure traffic.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Platform trust is becoming a security control failure when identity and content are conflated. This campaign works because chatgpt.com and claude.ai are treated as trusted by default, even when the content rendered inside them is malicious. That means the real control gap is not simply malware detection, but the assumption that a trusted domain implies trusted content. Practitioners should treat platform trust as conditional, not absolute.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- Our research also found that 80% of organisations report AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: How should organisations respond when search ads lead to AI platform malware delivery?
A: They should treat sponsored search results as a high-risk intake path and pair user awareness with browser controls that inspect downloads and execution prompts. The goal is to stop the trust chain before the user reaches the payload, not after the malware has already been staged.
👉 Read our full editorial: LLMShare attacks turn trusted chatbot pages into malware delivery
Platform trust is becoming a security control failure when identity and content are conflated. This campaign works because chatgpt.com and claude.ai are treated as trusted by default, even when the content rendered inside them is malicious. That means the real control gap is not simply malware detection, but the assumption that a trusted domain implies trusted content. Practitioners should treat platform trust as conditional, not absolute.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- Our research also found that 80% of organisations report AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: How should organisations respond when search ads lead to AI platform malware delivery?
A: They should treat sponsored search results as a high-risk intake path and pair user awareness with browser controls that inspect downloads and execution prompts. The goal is to stop the trust chain before the user reaches the payload, not after the malware has already been staged.
👉 Read our full editorial: LLMShare attacks turn trusted chatbot pages into malware delivery
Trusted-domain abuse has become a delivery control problem, not just a phishing problem. The decisive issue is no longer whether a domain is registered to a legitimate platform, because attackers are now using legitimate platforms as the first stage of the kill chain. Domain reputation and URL categorisation still matter, but they are insufficient when the abuse begins inside a trusted shared-content surface. Practitioners should treat platform trust as an attack surface in its own right.
A question worth separating out:
Q: How can organisations reduce risk from malvertising that targets AI tool users?
A: Organisations should monitor sponsored search results, block risky download paths, and train users to distrust installation instructions delivered through shared chatbot links. The goal is to break the conversion path from search intent to terminal-paste or download execution before the malicious page becomes the trusted step in the chain.
👉 Read our full editorial: LLMShare attacks turn trusted chatbot pages into malware delivery