Fake ChatGPT, Gemini and Claude Sites Steal Advertising Accounts and MFA Codes
A new phishing campaign targeting advertising account managers uses fake ChatGPT, Gemini, Claude, and Perplexity websites to steal login credentials and multi-factor authentication (MFA) codes through a browser-in-the-browser (BitB) attack.
Researchers found that the campaign also uses the recently released Muse AI agent, which Meta describes as an assistant for a variety of personal tasks.
The malicious pages target agency staff, media buyers, and administrators who manage accounts for multiple downstream clients. These accounts often contain advertising balances that attackers can use to run fraudulent campaigns or resell to other cybercriminals at high prices.
Fake AI tools target advertising professionals
The phishing sites claim that the fake AI products can help advertisers contact buyers, generate ad summaries, and plan and audit advertising campaigns and spending.
To access these features, visitors are asked to connect their advertising accounts to the fake AI product. When users click the Connect button, a fake Google login window opens inside the webpage and displays accounts.google.com in its address bar.

Source: Island
How the browser-in-the-browser phishing attack works
Browser-in-the-browser is a phishing technique developed by cybersecurity researcher Mr. dox and released in March 2022. The attack creates a fake browser window inside a legitimate browser window and displays a fraudulent login page.
The fake window resembles a real login popup, including a realistic title, interface, and login URL. However, it is simply an iframe designed to capture the victim’s credentials. The technique has been used extensively, including in attacks targeting Steam accounts.
Researchers at browser security firm Island say the attackers use kits that adapt the fake interface for Windows, macOS, iOS, and Android. The kits also support browser styling and dark mode.
After a victim enters the BitB flow, a human operator takes control and determines what the victim sees next. The attacker can:
- Prompt for a password up to three times.
- Request an SMS or verification code to bypass MFA protection.
- Display an Okta push request.
- Show a Google authorization prompt.
- Present a QR code.
Operators can also reject a submitted code, keep the victim on a waiting screen, or terminate and suppress the phishing flow at any time.

Source: Island
Broader phishing campaign uses job and refund lures
After investigating the campaign’s infrastructure, researchers found that it was part of a larger operation using multiple lures, including fake job opportunities and refund pages.
Pages associated with the operation share a Next.js and Socket.IO stack, common API endpoints, and, in many cases, a Vercel frontend with a railroad or rendering backend.

Source: Island
The attackers exposed outdated source code through a misconfigured public GitHub repository. Researchers traced the activity back to March, allowing them to connect the fake AI campaign to the broader operation.
Researchers also found that the Telegram control channel used by the attackers received hundreds of victim transmissions. However, this figure does not necessarily represent the number of accounts that were successfully compromised.
How to spot a fake browser login window
Although browser-in-the-browser attacks are deceptive, they can be identified because fake iframe-based windows cannot be moved or resized outside the browser window.
Moving or resizing a login window are actions supported by legitimate browser popups but not by BitB windows. Users should also be cautious when an unfamiliar AI service asks them to connect advertising, social media, or identity accounts.
Island researchers found that the phishing platform supports sign-in workflows for Google, Meta, TikTok, and Okta. Commands are sent through Socket.IO events.
“Unlike transparent reverse proxy kits, the Visible Platform rebuilds the provider interface locally and collects credentials and MFA status through its own API,” researchers say in their report.
This approach makes the traffic appear to come from an AI product communicating with an unrelated application backend.
Researchers identified dozens of URLs used in campaigns focused on advertising, refunds, and recruitment. The report includes a list of all URLs associated with the activity.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



