Weaponised ChatGPT Download Site Spreads Malware Through Sponsored Search Ads
A fake ChatGPT download page is being pushed through sponsored search results, turning a routine search for an AI tool into a malware risk for both Windows and macOS users.
Security researchers from Evalian’s SOC team identified the malvertising campaign, which uses paid search placement and convincing OpenAI-style visuals to attract people looking for legitimate ChatGPT downloads. The operation centres on the malicious domain `openew[.]app`, a site designed to look like an official ChatGPT download page.
Visitors are offered several download choices, including Windows, macOS, and a Chrome extension. That range matters. It suggests the campaign is not aimed at one narrow group of users. It is built to catch anyone searching for ChatGPT software, whether they are using a PC, a Mac, or a browser-based workflow.
This is a familiar tactic with a new lure. Attackers follow demand. When a product becomes popular enough that millions of people search for it by name, fake download pages and sponsored links become an efficient way to reach victims before they reach the real site.

The campaign uses search intent against the victim
The strength of this campaign is not technical novelty. It is timing and placement.
People searching for “ChatGPT download” or similar terms are already trying to install something. They are not being interrupted by a random pop-up or a suspicious message from an unknown sender. They have a clear goal, and a sponsored result at the top of a search page can appear to meet that goal.
That creates a dangerous shortcut. A victim sees what looks like a relevant result, opens a polished page, and clicks a download button that appears to match their device.
Evalian’s SOC team reported that the fake site closely mimics an official ChatGPT download page. It uses OpenAI-related visual cues and familiar product language to reduce suspicion. The domain itself, `openew[.]app`, appears designed to look plausible at a glance, especially when viewed quickly in a search result.
The use of sponsored search results is also important. Many users have learnt to be cautious with unknown emails or text messages. Fewer treat search ads with the same suspicion, even though attackers can abuse ad systems to place malicious links above genuine results.
The result is a neat chain:
A user searches for a legitimate AI tool.
A sponsored result appears near the top.
The page looks official enough to trust.
The download options match common platforms.
The installed file delivers malware instead of the expected app.
That chain is short, and every step feels normal to the victim.
Why fake ChatGPT download pages are so effective
ChatGPT’s popularity gives attackers a ready-made pool of targets. It is used by students, developers, writers, analysts, small businesses, and home users. Many of them move between the browser version, mobile apps, desktop clients, browser extensions, and third-party tools.
That mix creates confusion. Some people know there is an official ChatGPT web app. Others expect a desktop installer. Some search for a browser extension because they want AI help inside other sites. Attackers use that uncertainty.
A fake page with several download buttons can appear helpful rather than suspicious. The Windows and macOS options make the site look complete. The Chrome extension option adds another layer of credibility because many legitimate tools offer browser extensions.
The risk is highest when users assume that a high search ranking means a safe result. Search engines do remove malicious ads and domains, but detection is not instant. Attackers can register new domains, rotate infrastructure, change payloads, and run short-lived campaigns. By the time a malicious advert is reported and removed, some users may already have downloaded the file.
This is why a weaponized ChatGPT download site promoted through search ads can work so well. It inserts itself at the exact moment a user is ready to trust, click, and install.

The download options widen the attack surface
The fake `openew[.]app` page gives victims multiple installation paths. That matters because each platform has different security assumptions.
Windows downloads remain a common target
Windows malware delivery through fake installers is a long-running pattern. A user expects an `.exe` or `.msi` file, downloads it, approves prompts, and may ignore warnings if the page looked trustworthy.
Attackers can bundle malware with something that appears to install normally. In other cases, the visible installer may fail while the malicious component runs in the background. Without details of the exact payload from this campaign, the safest assumption is that any file obtained from the fake site should be treated as hostile.
Common outcomes from malicious installers can include:
Theft of browser cookies and saved credentials
Installation of remote-access tools
Download of further malware
Collection of system information
Attempts to disable security tools
Those behaviours vary by campaign, but the delivery route is clear. The fake installer is the entry point.
macOS users are not outside the risk
macOS users sometimes assume malware campaigns are mainly a Windows problem. This campaign challenges that assumption by offering a macOS download as part of the same fake ChatGPT site.
macOS has security controls such as Gatekeeper and notarisation checks, but users can still be tricked into bypassing warnings. Attackers often rely on instructions that tell victims to open a file in a specific way, grant permissions, or ignore a prompt that appears during installation.
The rise of cross-platform tools has made this more common. If a popular service has users on both Windows and macOS, attackers can build pages that target both at once.
Fake Chrome extensions can be especially intrusive
The Chrome extension option is also serious. Browser extensions can request access to browsing data, page content, clipboard activity, and site interactions, depending on the permissions granted.
A malicious extension does not need full system control to cause harm. If it can read data entered into web pages, redirect searches, inject content, or collect session information, it can be valuable to attackers.
This is why extension permissions deserve the same scrutiny as downloaded apps. A familiar-looking name is not enough. The publisher, reviews, install source, and permission list all matter.
Sponsored results need the same caution as unknown links
Sponsored search ads can be useful, but they are not a trust seal. They show that someone paid for placement. They do not prove that the destination is authentic.
Malvertising campaigns often exploit small differences that are easy to miss:
Legitimate behaviour | Risky behaviour |
Visiting the official product site directly or through a verified source | Clicking the first sponsored result without checking the domain |
Downloading from a known app store or vendor page | Installing from a newly registered or unfamiliar domain |
Reviewing extension permissions before installation | Accepting broad browser access because the name looks familiar |
Stopping when security warnings appear | Following page instructions that explain how to bypass warnings |
The challenge is that sponsored results can look clean and professional. A malicious page may use polished copy, modern design, and product screenshots. It may even include privacy claims, download buttons, and platform icons.
That visual polish is part of the trap. Attackers do not need to defeat every security control if they can persuade the user to make the unsafe choice voluntarily.

How to recognise a fake AI download site
Most users cannot inspect malware samples or trace campaign infrastructure. They can still spot many fake download pages before harm is done.
Start with the domain. An official product page should use a domain controlled by the vendor. For ChatGPT, users should navigate through OpenAI’s official website or trusted app store listings instead of relying on lookalike domains. A domain such as `openew[.]app` should raise suspicion because it is not an official OpenAI domain.
Next, look for pressure and shortcuts. Fake download pages often push users straight to installation with little context. They may present oversized buttons, multiple device options, and minimal support information. They may also provide instructions to bypass browser or operating system warnings.
Check the source of browser extensions. A Chrome extension should be found through the Chrome Web Store, with a clear publisher and permissions that match the function. Even then, users should be cautious with extensions that request broad access to all websites.
Pay attention to file names and signing details. A legitimate desktop application normally has consistent naming, publisher information, and distribution channels. If a file arrives from an unfamiliar domain, has a vague name, or triggers reputation warnings, stop.
For organisations, this type of campaign should also inform security monitoring. A search-led infection may not begin with email, so mail filtering will not catch it. Web filtering, DNS controls, endpoint detection, and user reporting all play a role.
What to do if the fake site was visited or a file was installed
Visiting a fake page does not always mean a system is infected. Downloading and running an installer is more serious. Installing a browser extension from a malicious source is also serious because it may have access to active sessions and sensitive content.
A sensible response starts with containment:
Disconnect the affected device from the network
This can limit communication with attacker-controlled servers while the device is assessed.
Do not enter more passwords on the device
If malware is present, new logins may be captured.
Remove suspicious extensions
Check the browser’s extension page and remove anything installed from the fake download flow.
Run a trusted security scan
Use an installed security tool or a known vendor product downloaded from a clean device.
Change important passwords from a separate trusted device
Start with email, password managers, banking, cloud storage, and work accounts.
Revoke active sessions where possible
Many services allow users to sign out of all devices. This can reduce the value of stolen cookies or session tokens.
Report the advert and domain
Search engines, browser vendors, security teams, and hosting providers can use reports to remove malicious infrastructure faster.
For businesses, employees should report suspected downloads quickly, even if they are embarrassed or unsure. Fast reporting gives security teams more options and reduces the chance of a single infection spreading.
Why this campaign is part of a larger pattern
This incident is not just about one domain. It reflects a wider shift in how attackers use trusted online routines.
Search has become a default path to software. People often search for a product name rather than typing a known web address. Attackers know this. They target searches for remote access tools, password managers, cryptocurrency wallets, productivity apps, and now AI services.
The move to AI-themed lures is predictable. AI tools are popular, new features launch often, and users expect rapid changes. That lowers suspicion when a page offers a new app, extension, or platform-specific download.
The campaign also shows why brand impersonation remains so effective. Attackers do not need perfect copies. They need enough familiarity to carry the victim through the next click. A similar name, a clean layout, and a credible download path can be enough.
A polished search ad should never be treated as proof that a download is safe.
Security awareness often focuses on phishing emails, but search-led malware deserves equal attention. It meets users in a place they already trust and during an action they already planned to take.

The safest route to ChatGPT and other AI tools
The practical defence is simple, but it requires a habit change. Do not start sensitive software downloads from sponsored results. Use official websites, verified app stores, or trusted internal software portals.
For ChatGPT, type the official OpenAI address directly into the browser or use a trusted bookmark. For mobile apps, use the official Apple App Store or Google Play listing and check the publisher before installing. For browser extensions, review the publisher, permissions, and source carefully.
Security teams should also consider blocking known malicious domains, monitoring for unusual downloads from newly seen domains, and educating users that sponsored results can be abused. Clear guidance helps. A short internal note saying “use this official link for ChatGPT” can prevent risky searches.
This campaign succeeds because it blends into a normal task. That is what makes it dangerous. The best response is to slow the task down at the moment of download, check the source, and treat lookalike domains as a warning sign rather than a convenience.





Comments