Cybercriminals are increasingly exploiting AI-driven platforms and search results to conduct scams and distribute malware. Researchers have identified a technique called 'LLM phone number poisoning,' where attackers manipulate public web content to ensure that AI chatbots and search engines, such as Google's AI Overview and Perplexity's Comet browser, surface fraudulent customer support numbers as legitimate contact information. This manipulation leverages Generative Engine Optimization (GEO) and Answer Engine Optimization (AEO) to poison the data sources that large language models (LLMs) use, putting users at risk of being directed to scam call centers or phishing sites.
In a related trend, attackers are also abusing the chat-sharing feature of the official ChatGPT website to host malicious guides that distribute infostealer malware targeting macOS users. By purchasing sponsored ads for search terms like 'chatgpt atlas,' threat actors lure victims to what appears to be a legitimate ChatGPT domain, where a shared chat contains instructions and links to download malware disguised as the 'Atlas browser.' These campaigns highlight the growing risk of AI platforms being weaponized for both social engineering and malware distribution, exploiting user trust in reputable AI services and search results.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes reported that poisoned public AI chats were appearing in Google results and detailed a multi-stage AMOS deployment using base64-decoded payloads, malicious bash scripts, privilege escalation, and persistence. It also linked the broader campaign to the fake "OpenAI Atlas browser for macOS" variant and published remediation advice for suspected infections.
Follow-on reporting said Huntress confirmed the AMOS campaign was broader than a single lure, with malicious shared ChatGPT and Grok guides targeting users searching for macOS troubleshooting advice. The analysis added technical details including LaunchDaemon persistence, crypto-wallet trojanization, and AMOS's newer backdoor capabilities.
Researchers at Aurascape's Aura Labs identified a separate AI-abuse technique in which attackers seed fraudulent phone numbers across public websites so LLM-based assistants and AI search tools return scam contact details to users. They observed real cases involving fake airline customer support numbers surfaced by AI systems.
Kaspersky reported a new ClickFix-style campaign abusing ChatGPT's chat-sharing feature and paid Google search ads to deliver AMOS and a persistent backdoor from attacker-controlled infrastructure. The company described how victims were tricked into running shell commands from a shared ChatGPT conversation hosted on a legitimate domain.
Threat actors began using Google ads, SEO poisoning, and shared ChatGPT and Grok conversations to lure macOS users seeking troubleshooting help into copying Terminal commands that install the Atomic macOS Stealer (AMOS). The campaign included fake guides such as an "Atlas browser for macOS" installation and other macOS help topics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourceeclecticlight.co
Open sourcebleepingcomputer.com
Open sourcezdnet.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.