In an alarming development for the digital advertising landscape, cybersecurity researchers have unearthed a highly sophisticated, human-operated phishing platform. This elaborate scheme capitalizes on the burgeoning popularity of artificial intelligence (AI) chatbots, impersonating leading platforms like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus to ensnare unsuspecting users and pilfer their critical credentials and multi-factor authentication (MFA) codes.
The Deceptive Lure: AI Ad Portals
The attackers craft convincing fake advertising products, promising enticing features such as campaign optimization, spend audits, and seamless business-account connections. However, these seemingly legitimate portals harbor a singular, malicious intent: to harvest sensitive user data. The core of their deception lies in a cunning technique known as “browser-in-the-browser” (BitB) trickery.
Unmasking the Browser-in-the-Browser (BitB) Attack
Island researchers Oleg Zaytsev and Ofek Ronen detailed the mechanics of this sophisticated attack. Upon clicking a “Connect” button—a central feature across these fake AI products—victims are presented with a seemingly authentic login window. Crucially, this window is not a new browser tab or pop-up, but rather a meticulously drawn imitation within the real browser window. While the fake address bar displays trusted origins like “accounts.google.com” or an Okta tenant, the user’s actual browser remains on the malicious phishing domain.
“Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next,” the researchers revealed. This real-time interaction underscores the advanced nature of the threat.
A Human Touch: Real-time Credential Harvesting
One prominent example cited is “museads.ai,” which surfaced shortly after Meta launched its AI agent, Muse. Posing as “Your AI ads manager for paid media workflows,” this platform, like others, features a “Connect” button that initiates the BitB attack. This allows the attackers to capture credentials for Google, Meta, TikTok, and Okta accounts. As victims attempt to log in, their device is fingerprinted, and this data is transmitted to the attacker. Armed with these credentials, a human operator then attempts to log into the victim’s account in real-time.
The phishing page communicates with the operator via Socket.IO events, enabling them to dynamically steer the victim through the authentication process. Zaytsev explained, “The commands let the operator steer the victim through authentication in real time: request another password (/password), show an SMS or authenticator challenge (/2fa, /authApp), display Google prompts such as approval, QR, or number matching (/googlePrompt, /googleQrVerify, /verifyTap), or select Okta username, password, SMS, push, authenticator, and number-matching screens… The operator can also reject a submitted code (/wrong2fa), keep the visitor waiting, or end or suppress the flow.” This level of control makes the attacks highly adaptive and difficult to detect for the average user.
Tailored Deception: Every Brand, Its Own Pitch
The attackers meticulously craft unique narratives for each impersonated AI brand. ChatGPT, for instance, promises a Monday Google Ads brief, while Gemini offers MCC (manager account) and linked-client support. Claude receives its own advertising portal, Perplexity touts campaign planning and spend audits, and Manus provides a private Meta integration. These bespoke pitches, often delivered via fake invitation emails, lend a false sense of legitimacy to the attacks, making them more effective.
Part of a Broader Phishing Ecosystem
Island’s investigation reveals that these AI ads pages are merely one facet of a larger, multi-pronged phishing operation. The same platform also supports Google Ads-themed refund claims and payment confirmations, alongside recruitment-related scams impersonating high-profile brands like Tesla, Louis Vuitton, Nike, and Adecco. A common technological thread—Next.js and Socket.IO—and shared communication endpoints link all these malicious websites, suggesting a coordinated effort by a single threat actor group. Disturbingly, earlier versions of the platform’s source code were even exposed through misconfigured public GitHub repositories, offering a glimpse into the attackers’ methods.
Who’s at Risk and Why?
The AI ads-focused campaign specifically targets agency staff, media buyers, and manager-account administrators. The ultimate goal is to hijack these valuable ad accounts, either to run unauthorized ad campaigns for the attackers’ benefit or to sell them on the dark web, particularly if they boast a clean spend history. This aligns with a growing trend: a July 2026 report by Mimecast highlighted how malware families like VietCredCare, DuckTail, NodeStealer, and PXA Stealer have fueled widespread ad account theft, transforming it into a “commodity crime” that drains business budgets across the advertising ecosystem.
As the digital landscape continues to evolve with AI at its forefront, the sophistication of cyber threats also escalates. Vigilance, robust security practices, and a healthy skepticism towards unsolicited offers remain paramount in protecting digital assets from such insidious attacks.
For more details, visit our website.
Source: Link










Leave a comment