Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
search-ad-manipulationai-enabled-threat-activitycredential-stealer-activityvoice-social-engineering

Cybercriminal Abuse of AI Platforms and Search Results for Scams and Malware

Updated 3mo agoFirst seen Dec 9, 20255 sources

Cybercriminals are increasingly exploiting AI-driven platforms and search results to conduct scams and distribute malware. Researchers have identified a technique called 'LLM phone number poisoning,' where attackers manipulate public web content to ensure that AI chatbots and search engines, such as Google's AI Overview and Perplexity's Comet browser, surface fraudulent customer support numbers as legitimate contact information. This manipulation leverages Generative Engine Optimization (GEO) and Answer Engine Optimization (AEO) to poison the data sources that large language models (LLMs) use, putting users at risk of being directed to scam call centers or phishing sites.

In a related trend, attackers are also abusing the chat-sharing feature of the official ChatGPT website to host malicious guides that distribute infostealer malware targeting macOS users. By purchasing sponsored ads for search terms like 'chatgpt atlas,' threat actors lure victims to what appears to be a legitimate ChatGPT domain, where a shared chat contains instructions and links to download malware disguised as the 'Atlas browser.' These campaigns highlight the growing risk of AI platforms being weaponized for both social engineering and malware distribution, exploiting user trust in reputable AI services and search results.

Share:
Cybercriminal Abuse of AI Platforms and Search Results for Scams and Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 12, 20256mo ago

Malwarebytes documents additional AMOS variants and infection-chain details

Malwarebytes reported that poisoned public AI chats were appearing in Google results and detailed a multi-stage AMOS deployment using base64-decoded payloads, malicious bash scripts, privilege escalation, and persistence. It also linked the broader campaign to the fake "OpenAI Atlas browser for macOS" variant and published remediation advice for suspected infections.

Dec 10, 20256mo ago

Huntress and BleepingComputer expand analysis of AMOS AI-chat malvertising

Follow-on reporting said Huntress confirmed the AMOS campaign was broader than a single lure, with malicious shared ChatGPT and Grok guides targeting users searching for macOS troubleshooting advice. The analysis added technical details including LaunchDaemon persistence, crypto-wallet trojanization, and AMOS's newer backdoor capabilities.

Dec 9, 20257mo ago

Aurascape discloses 'LLM phone number poisoning' scam technique

Researchers at Aurascape's Aura Labs identified a separate AI-abuse technique in which attackers seed fraudulent phone numbers across public websites so LLM-based assistants and AI search tools return scam contact details to users. They observed real cases involving fake airline customer support numbers surfaced by AI systems.

Kaspersky identifies ChatGPT share abuse in a ClickFix-style AMOS campaign

Kaspersky reported a new ClickFix-style campaign abusing ChatGPT's chat-sharing feature and paid Google search ads to deliver AMOS and a persistent backdoor from attacker-controlled infrastructure. The company described how victims were tricked into running shell commands from a shared ChatGPT conversation hosted on a legitimate domain.

Attackers poison AI chats and search results to spread AMOS on macOS

Threat actors began using Google ads, SEO poisoning, and shared ChatGPT and Grok conversations to lure macOS users seeking troubleshooting help into copying Terminal commands that install the Atomic macOS Stealer (AMOS). The campaign included fake guides such as an "Atlas browser for macOS" installation and other macOS help topics.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Malware
1 linked
Affected products
6 linked
MalwarebytesGithubMacosChatgptChatgptGoogle Search
Organizations
17 linked
GoogleKasperskyOpenaiAppleXMalwarebytesxAIConsensysSatoshilabsEmirates AirlinesBritish AirwaysPerplexityHuntressLedgerAMOS (Atomic macOS Stealer)YelpAurascape
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cybercriminal Abuse of AI Platforms and Search Results for Scams and Malware | Mallory