Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Zbtlink Router Backdoor Affects 20+ Models
August 7, 2026
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Home/Threats/Threat Actors Phish Credentials Using Fake ChatGPT, Claude, DeepSeek Brands
Threats

Threat Actors Phish Credentials Using Fake ChatGPT, Claude, DeepSeek Brands

Key Takeaways Cybercriminals are exploiting the popularity of AI platforms like ChatGPT, Claude, and DeepSeek to launch sophisticated phishing and malware campaigns. These attacks leverage social...

Sarah simpson
Sarah simpson
June 9, 2026 4 Min Read
55 0

Key Takeaways

  • Cybercriminals are exploiting the popularity of AI platforms like ChatGPT, Claude, and DeepSeek to launch sophisticated phishing and malware campaigns.
  • These attacks leverage social engineering, impersonating official communications and services to trick users into divulging credentials, credit card details, and authentication tokens.
  • Attack chains are increasingly complex, routing victims through legitimate services such as URL shorteners and CRM tools to evade detection.
  • Thousands of organizations globally have been targeted, with some campaigns deploying infostealers like Vidar.

Cybersecurity analysts have uncovered a new wave of attacks where threat actors are leveraging the prominent branding of leading artificial intelligence platforms, including ChatGPT, Claude, and DeepSeek, to execute elaborate phishing and malware distribution schemes. These campaigns are meticulously crafted to deceive users into surrendering sensitive information such as login credentials, credit card numbers, and authentication tokens.

Table Of Content

  • Key Takeaways
  • Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands
  • Fake DeepSeek Installer and Malvertising Drop Vidar
  • What You Should Do

The rapid integration of AI tools into daily routines has created a fertile environment for malicious actors. As millions adopt AI assistants, many users are still learning to distinguish authentic communications from fraudulent attempts, presenting a prime opportunity for exploitation.

Attackers capitalize on this by designing fake web pages or emails that mimic trusted AI platforms. A significant number of users, unaware of the deception, proceed to click on malicious links or download compromised files.

Microsoft Threat Intelligence analysts documented several of these campaigns that transpired in early 2026. Microsoft clarified in a report shared with Cyber Security News (CSN) that these operations do not signify any breaches of the AI services themselves. Instead, they are purely social engineering endeavors that exploit established brand trust to coax users into clicking malicious links, opening infected PDFs, or downloading malware.

A notable characteristic of these attacks is their enhanced stealth. Threat actors are routing victims through legitimate, trusted online services before ultimately redirecting them to malicious destinations. This layered approach complicates detection efforts.

Services such as URL shorteners, customer relationship management (CRM) platforms, and even GitHub are integrated into the attack chain to mask the true origin and nature of the malicious content. By the time victims discern the fraudulent nature of the interaction, their sensitive information may have already been compromised. The repercussions of these attacks are significant, with thousands of organizations across numerous countries targeted, leading to losses of credit card data, account access, and authentication tokens that provide direct entry points into corporate systems.

Threat Actors Abuse ChatGPT, Claude, and DeepSeek Brands

One illustrative example is a ChatGPT-themed campaign identified on May 5, 2026. This operation involved approximately 4,500 emails sent to targets in South Africa. The emails falsely warned recipients that their ChatGPT Plus subscription was at risk of downgrade unless they updated their payment method within seven days. These emails featured the authentic ChatGPT logo and a seemingly legitimate “update” button.

Clicking this button did not immediately lead to a malicious site. Instead, victims were routed through a complex chain involving a CRM service, an Amazon tracking domain, and a URL shortener before finally landing on a compromised website. This site hosted a fake payment page within a subfolder, complete with a deceptive CAPTCHA to deter automated scanners. The page then proceeded to collect personal details and full credit card information over a two-step process.

Another campaign, leveraging the Claude brand, was active from April 20 to 22, 2026, impacting over 2,000 organizations in the United States, the United Kingdom, and India. Emails in this campaign alleged that the recipient’s account had violated usage policies. An attached PDF, titled “Fill and Sign Claude Appeal Form.pdf,” directed users to an attacker-controlled domain. Following a series of fake verification screens, victims were ultimately redirected to what appeared to be a Microsoft sign-in page, specifically designed to steal access tokens.

Fake DeepSeek Installer and Malvertising Drop Vidar

In April 2026, threat actors swiftly capitalized on the preview release of DeepSeek’s V4 model. Within 45 minutes of the announcement, a fraudulent GitHub organization named DeepSeek-V4 was established. This fake repository incorporated stolen branding, legitimate benchmark data, and search-optimized tags to achieve high rankings in both traditional and AI-driven search results. Users who downloaded archives from this repository inadvertently received a loader that silently installed the Vidar infostealer onto their devices.

Concurrently, a separate malvertising campaign, attributed to Storm-3075, promoted a bogus product called “Awesome AI Windows Plugin” via free movie streaming websites. The download provided was a fraudulently code-signed executable, linked to Fox Tempest, a group known for operating a malware-signing service utilized by various criminal actors. Upon launching the file and clicking a “Continue” prompt, a Python downloader discreetly retrieved the Vidar infostealer from an attacker-controlled server.

What You Should Do

  • Enable multi-factor authentication (MFA) on all accounts to add an essential layer of security.
  • Exercise extreme caution with unsolicited emails and messages; avoid clicking suspicious links or downloading attachments from unknown sources.
  • Always verify communications from AI platforms by directly visiting their official websites rather than relying on links provided in emails.
  • Organizations should implement robust email link scanning tools and solutions capable of detecting and blocking phishing pages before they reach end-users.
  • Regularly update operating systems, applications, and security software to protect against known vulnerabilities.
  • Educate users on the tactics of social engineering and the importance of recognizing phishing attempts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Apache HTTP Server 2.4.58 Patches Critical Use-After-Free, DoS, XSS

Next Post

SAP Patches Critical NetWeaver Vulnerabilities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Flaws in Anthropic, Google, OpenAI Coding Agents Allow RCE
August 6, 2026
Best Intrusion Detection & Prevention (IDS/IPS) Tools for 2026
August 6, 2026
Critical WSUS Vulnerability Lets Attackers Compromise Enterprise Endpoints
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us