← Blog
For individuals

You Searched "Download ChatGPT." A Fake Site Was Waiting.

Explore an AI summary

Key takeaways

  • Attacks disguised as popular AI tools have exploded. Kaspersky counted more than 33,000 in the first four months of 2026, roughly five times the year before.

  • The lures impersonate the biggest names: ChatGPT, Claude, Gemini, Grok, DeepSeek, Perplexity, Cursor, and more.

  • On a fake ChatGPT site, Windows visitors got a password-stealing loader and Mac visitors got crypto-stealing malware that even swaps your real wallet apps for fake ones.

  • Attackers buy search ads and abuse trusted hosts (even a real AI platform's own share links) so the fake page looks legitimate, padlock and all.

  • The reliable defense is at the page and the download. Haven helps in two ways: it flags the fake site for you, and on unverified sites it pauses downloads so you can see what is about to land on your device.


You want to try a new AI tool, so you search "download ChatGPT" or "install Claude," click a result near the top, and run the installer. It looks right: the branding, the layout, the padlock in the address bar. But the app you just installed is not the AI tool. It is malware built to empty your saved passwords, your browser sessions, and your cryptocurrency wallet.

This is now one of the fastest-growing scams online, because nobody knows the official download page for a brand-new AI tool yet. Three separate security teams have documented it from different angles. Here is how the fake AI tool download scam works, why it spreads so fast, and how to get the real app instead.


Why AI tools are the perfect bait

Most software has trusted download habits built around it. If you want Chrome, you go to Google. If you want Photoshop, you go to Adobe. You already know where the real download lives.

AI tools are different. Most people are installing them for the very first time, so they rely on a search, an ad, a YouTube link, or a post to find the download. And these products launch and change constantly, ChatGPT, Claude, Gemini, Sora, DeepSeek, and others, so every new release sends a fresh wave of people searching "download [name]" without knowing the official web address. That search traffic is exactly where attackers set up shop.

The fakes do not even need to be sophisticated, because real AI product pages are minimal by design: a logo, some copy, and a big download button. A copied page matches what you expect to see, with no broken English and no aggressive pop-ups, just familiar branding and the reassuring padlock.

The scale is not hypothetical. Kaspersky, in its 2026 report on threats to small and medium businesses, found more than 33,000 attacks in the first four months of 2026 that were disguised as five popular AI tools (ChatGPT, DeepSeek, Grok, Claude, and Gemini). That is nearly five times the same period a year earlier.


What actually happens: a fake ChatGPT site, two payloads

Malwarebytes documented a clear example: a site at a lookalike domain that closely mimicked OpenAI's real ChatGPT download page, complete with dark theme, familiar branding, and download buttons for both Windows and Mac. Like real software, it served a different installer for each platform. That is what made it convincing.

On Windows, clicking download delivered a fake installer that quietly opened a channel to an attacker's server and began stealing credentials and browser data.

On Mac, it delivered something more expensive and more targeted: a strain of crypto-stealing malware (a fork of the well-known AMOS family). It copied the Mac keychain, harvested saved logins and cookies from more than a dozen browsers, grabbed Telegram sessions, and scanned for cryptocurrency wallets like Ledger Live, Trezor Suite, Exodus, and Electrum. Then came the nastiest part: it tried to delete your real wallet apps and replace them with trojanized copies, so the next time you opened "Ledger Live," you were opening the attacker's version.

The tell that would have stopped all of it was the same in every case: the download did not come from the AI vendor's real, official website.


The new twist: ads and trusted domains

Getting you to the fake page is the attacker's main job, and they have gotten good at it.

Trend Micro tracked a campaign that bought Google search ads impersonating at least six AI developer tools, including Claude, ChatGPT Codex, Perplexity, Cursor, and JetBrains, funneling more than 2,000 victims toward malicious pages over about seven weeks. At first those pages were hosted on free, trusted infrastructure (subdomains of a well-known code-hosting service) so they slipped past filters. Then the campaign escalated in a way worth understanding: it started abusing a real AI platform's own "shared chat" links to host the lure. Victims landed on a genuine, trusted domain, which made the trap far harder to spot, and the security company that runs the platform later banned the accounts and tightened its rules once notified.

In that version, the page did not offer a download at all. It showed a fake "support" conversation telling the user to open Terminal and paste a command to "finish installing." That command quietly downloaded and ran the malware.

We will be honest about that last variant below, because it is a different kind of trap than a fake download button, and it is worth being clear about what a browser tool can and cannot do.


How Haven helps

For the core of this scam, the fake AI download page, Haven helps in the two moments that matter.

First, Haven flags the fake site for you. It analyzes the actual page in front of you, not just how it looks or how you got there, so when a page imitates ChatGPT, Claude, or another AI brand on a lookalike or unverified domain, Haven warns you before you click download, even when the page has a valid padlock and perfect branding.

Second, on unverified sites, Haven pauses downloads so you know what is about to land on your device. Instead of "ChatGPT.exe" quietly saving and running, you get a moment to see what it actually is and decide, rather than finding out later that it was a stealer. That pause is the difference between catching this and cleaning up after it.

Those two steps cover the exact gap here: the pages look legitimate and the files are freshly built, so the real protection is not trusting a fake AI page and not letting an unexpected download run unchecked. If you want to check a link from an ad or a post before you visit, you can also paste it into Haven's free link checker.

To be clear about scope, including where Haven does not help: Haven works in your browser, at the page and the download. It flags fake and unverified sites and pauses downloads there. It is not antivirus, so it does not scan a file's contents or remove malware already installed. And in the newer "paste this command into Terminal" version of the attack, there is no download for Haven to pause and the page may sit on a trusted domain, so the essential defense there is simple and human: never paste a command from a web page to "finish installing" software. Haven's strongest coverage is the fake download page, which is still how most of these attacks work.


How to download AI tools safely

A few habits keep you on the real thing:

  • Go to the official source. Type the vendor's real address yourself (for example, openai.com or anthropic.com) or use an official app store, rather than clicking a search result or ad.

  • Do not trust the padlock. A padlock only means the connection is encrypted, not that the site is genuine. Scam sites have padlocks too.

  • Be extra careful with brand-new AI tools. If you do not know the official URL, look it up from the company's verified site or social account before downloading.

  • Never paste a command into Terminal or PowerShell to "finish installing" an app. Real installers do not work that way, and this is a common trap.

  • Prefer official package managers (like the App Store, Microsoft Store, or brew/pip/npm for developers) over web-based install instructions.

  • If you already installed a fake AI app, treat the device as compromised: from a separate clean device, change passwords starting with your email, sign out everywhere, and if you hold cryptocurrency, move it immediately and do not reopen wallet apps on the affected machine.

The brand on the fake page will keep changing, ChatGPT today, the next hot AI tool tomorrow. The move underneath stays the same: impersonate a tool you want, get you to a fake page, and get you to install. Slow down at the page and the download, and it falls apart.


About Haven

Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link, enter your password, or download a file, flagging fake and impersonated login pages, suspicious links, and lookalike sites, and pausing downloads on unverified sites so you can see what is about to land on your device. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss.

Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.

Frequently asked questions

Is that "download ChatGPT" site real?
Only if it is OpenAI's official site (openai.com) or an official app store. Attackers run fake ChatGPT download pages that look identical to the real one, padlock included, and serve malware instead of the app. Because most people do not know the official URL for a new AI tool, these fakes rank in search and ads. Always type the vendor's real address yourself rather than clicking a search result.
How do fake AI app downloads steal your information?
The fake installer runs malware instead of the AI tool. On Windows it typically steals saved passwords, cookies, and browser sessions and opens a channel to an attacker's server. On Mac, documented campaigns steal keychain data, browser logins, and cryptocurrency wallets, and in some cases replace real wallet apps like Ledger Live and Trezor Suite with trojanized copies to drain funds.
Which AI tools are being impersonated in these scams?
Security researchers have seen lures impersonating ChatGPT, Claude, Gemini, Grok, DeepSeek, Perplexity, Cursor, ChatGPT Codex, and JetBrains, among others. Kaspersky counted more than 33,000 attacks disguised as popular AI tools in the first four months of 2026, about five times the year before, so the specific brand changes often while the scam stays the same.
Why didn't the padlock or my antivirus protect me?
A padlock only means the connection is encrypted; it does not verify that a site is the real vendor, and scam sites use padlocks too. Antivirus can help, but attackers build fresh installers that may not be recognized yet, and some versions trick you into pasting a command that runs malware without a traditional file. That is why avoiding the fake page and the unexpected download in the first place is the most reliable defense.
What are the two things Haven does to stop fake AI download scams?
First, Haven flags the fake or unverified AI download site for you, warning that a page imitating ChatGPT, Claude, or another brand is not the real one before you click download, even with a valid padlock. Second, on unverified sites it pauses downloads so you can see what is about to land on your device and decide. Haven works in the browser and is not antivirus, so it does not scan files or remove installed software, and it cannot stop a command you paste into your own Terminal.
Is Haven free?
Yes. Haven is free for individual use. Haven for Business extends browser-level protection to teams. Haven is operated by MirrorTab, Inc.