Fake ChatGPT, Gemini sites phish ad accounts and MFA codes
A phishing campaign is going after people who manage advertising accounts, using fake versions of ChatGPT, Gemini, Claude and Perplexity to capture login credentials and multi-factor authentication (MFA) codes. The pages rely on browser-in-the-browser (BitB) attacks, according to researchers at browser security company Island.
The operators timed part of the campaign to the recent launch of Muse, an AI agent that Meta describes as an assistant for a range of personal tasks.
Why ad accounts
The targets are agency employees, media buyers and administrators. Their accounts often reach into several downstream client accounts, which makes them valuable.
Once inside, attackers can usually spend the available balance on fraudulent ad campaigns. They can also sell the accounts to other criminals, often for large sums.
The fake AI tools are pitched at advertisers. They promise to help reach buyers, produce ad briefs, and plan and audit campaigns and spending. To use any of these features, the victim is told to connect their account. Clicking "connect" opens what looks like a Google sign-in window inside the page, with an address bar that shows accounts.google.com.
How the BitB trick works
Security researcher mr. dox described the browser-in-the-browser technique in March 2022. The attacker draws a fake browser window inside a real one and uses it to show a fraudulent login page.
The window looks like a normal login pop-up, with a believable title, interface and the URL the user expects to see. In reality it is an iframe built to capture whatever the victim types. The method has been used widely since then, including against Steam users.
Island says the kit in this campaign adjusts its interface for Windows, macOS, iOS and Android. It copies browser styling and supports dark mode.
A human at the controls
After the victim enters the BitB flow, a human operator takes over and decides what the victim sees next. The operator can:
- ask for the password up to three times
- request an SMS or authenticator code to get past MFA
- show Okta push requests or Google approval prompts
- display a QR code
- reject codes the victim submits
- keep the victim on a waiting screen
- end or suppress the phishing flow at any time
The platform supports Google, Meta, TikTok and Okta sign-in workflows. Commands are passed through Socket.IO events.
"Unlike a transparent reverse-proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs," the researchers wrote in their report.
This design hides the malicious traffic. To an observer, it looks like an AI product talking to an unrelated application backend.
Part of a bigger operation
Looking at the infrastructure, Island linked the AI lures to a larger operation that also used fake job offers and refund pages. All of these pages share a Next.js and Socket.IO stack and common API endpoints. Many sit on Vercel frontends with Railway or Render backends.
The link was possible because the attacker left older source code in misconfigured public GitHub repositories. That code allowed the researchers to trace the activity back to March.
The Telegram channel used to control the attacks had received hundreds of victim submissions. Island notes that this figure does not necessarily match the number of accounts that were actually compromised.
The researchers counted dozens of URLs across the ad, refund and recruitment campaigns. Their report lists all of them.
Spotting the fake window
BitB pages are convincing, but there is a simple test. A real OAuth pop-up is a separate browser window, so it can be dragged outside the main browser or resized. A BitB window is just an iframe inside the page and cannot do either. If a login pop-up refuses to leave the browser frame, it is fake.
Our Take
This campaign combines two things that work well for attackers right now: interest in new AI tools and the high value of shared business accounts. Fake AI products give a believable reason to ask for an account connection, and a single agency login can open access to many clients at once. For marketing teams, this suggests that ad platform accounts deserve the same protection as finance or admin accounts.
The human operator in the loop is the most worrying part. Because someone can reject codes, repeat password prompts and switch between Okta, Google and QR code challenges in real time, SMS and authenticator codes offer limited protection here. As with other phishing kits aimed at specific audiences, the lure changes while the backend stays the same, as seen in the reuse of one stack for ads, refunds and recruitment.
For now, the drag-and-resize test is a cheap defense that is worth teaching to staff. Checking unfamiliar links with tools such as URL reputation checkers can also help. It is worth watching whether the operators move to new AI product names as launches continue, and whether platforms such as Meta, Google and TikTok respond with stronger phishing-resistant sign-in options for advertising accounts.
