AI platforms abused in widespread cyber‑espionage campaigns
Security researchers have uncovered multiple campaigns that exploit popular artificial‑intelligence tools to steal credentials and deliver malware. Fake installers masquerading as Anthropic’s Claude have been used to harvest API keys from developers, while sponsored ads for a bogus "ChatGPT desktop app" redirect users to malicious downloads that steal passwords, crypto wallets and session tokens. These attacks, dubbed ClaudeBleed, LLMShare and ChatGPhish, leverage the trusted interfaces of AI assistants to bypass filters and trick users into executing harmful code.
Separately, Iranian state‑linked hacker groups are employing Western AI models such as ChatGPT, Gemini and other services to automate the creation of malware, craft highly convincing phishing emails in multiple languages, and even support missile and drone operations. The use of AI has accelerated their cyber‑operations, allowing rapid targeting of entities in the United States, Israel, the United Arab Emirates and elsewhere. Companies like OpenAI and Anthropic are scrambling to mitigate the abuses, but the campaigns highlight growing vulnerabilities as AI becomes integral to software development and daily online activity.