Fake ChatGPT Desktop App Ads Used to Push Password-Stealing Malware
2026-06-02T20:51:39Z•0e435aa6586e267bd98ebb062d4d1d54188887d8311b538b7137becb57795d24
AI-bot-exploitC2SteamWordPressXSSaccount-takeoverad-abusecredential-theftfake-appmalvertisingmalwarepatch-releasedphishingpretalxstealth-evasionthreat-intelzero-click
What happened
Multiple active threats reported: fake “ChatGPT” desktop app ads distributed password-stealing malware by abusing trusted AI links, hiding payloads from scanners and tricking users into downloads; attackers abused Meta’s AI support bot to bypass checks and hijack major Instagram accounts (issue observed in video evidence and later fixed by Meta); a WordPress malware campaign used Steam Community profile comments to encode and hide C2 instructions, impacting ~1,980 sites; and a zero-click XSS in pretalx allowed hijacking of conference organizer accounts (patched in v2026.1.0). These incidents涉及
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 0e435aa6586e267bd98ebb062d4d1d54188887d8311b538b7137becb57795d24
- Enrichment time
- 2026-06-02T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.