Cybersecurity Researchers Expose Sophisticated "Human-Operated" Phishing Platform Impersonating AI Ad Products

Cybersecurity researchers have uncovered details of an advanced, human-operated phishing platform that deploys sophisticated spoofed interfaces mimicking advertising products for major artificial intelligence chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.

The fraudulent products are designed to lure digital marketers, media buyers, and corporate technology teams by claiming to offer campaign optimization, advertising spend audits, and business-account integration. However, their singular objective is the large-scale capture of account credentials and multi-factor authentication codes through deceptive login windows executed via the browser-in-the-browser technique.

The operation was brought to light in a comprehensive report shared by Island researchers Oleg Zaytsev and Ofek Ronen. According to the findings, each fraudulent product centers around a singular user action: a prominent "Connect" button. When an unsuspecting visitor clicks this interface element, it triggers a sophisticated browser-in-the-browser attack, a method where a fake authentication window is drawn directly inside the legitimate browser frame. While the spoofed address bar displays trusted origins such as verified accounts domains or corporate Okta tenants, the underlying real browser remains firmly rooted on the attacker’s phishing domain.

Behind the polished and deceptive user interface, the underlying platform operates with high efficiency. It logs every attempted password entry, creates a comprehensive digital fingerprint of the victim’s device, and allows a human operator to monitor the interaction in real-time, deciding precisely which multi-factor authentication challenge the victim should encounter next.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

The speed at which these fraudulent setups adapt to real-world technology releases underscores the agility of the threat actors behind them. For instance, researchers identified a specific domain, "museads.ai," which abruptly emerged online on September 16, 2026—just over a week after Meta officially launched Muse, its dedicated AI agent designed for personal and professional workflows. Promoted as an artificial intelligence advertising manager tailored for paid media workflows, the fraudulent platform lured prospective users with promises of helping them efficiently reach buyers, seamlessly connect advertising accounts, and execute sponsored placements across digital channels.

Upon visiting the site, users were greeted by a deceptive prompt box featuring the signature "Connect" button. Engaging with this button instantly launched the browser-in-the-browser attack, generating a bogus account sign-in form explicitly styled to target credentials for Google, Meta, TikTok, and corporate Okta workflows, complete with an address bar falsely pointing to legitimate infrastructure like accounts.google.com.

While the victim interacts with the fake login screen, background scripts capture device fingerprint data and transmit it directly to the attacker’s endpoint over Socket.IO. Armed with freshly harvested account credentials, the human operators immediately attempt real-time logins to compromise the targeted profiles.

The campaign’s versatility is reflected in the tailored pitches assigned to each major technology brand. Researchers noted that every brand featured in the platform receives its own specialized narrative. ChatGPT promises a Monday Google Ads brief, while Gemini lures users with manager account and linked-client support. Similarly, Claude is outfitted with its own bespoke advertising portal, Perplexity offers comprehensive campaign planning and spend audits, and Manus is presented as offering a private Meta integration.

To drive traffic to these meticulously crafted landing pages, targets are typically directed via fraudulent invitation emails designed to impersonate trusted technology brands, lending the malicious infrastructure a high veneer of corporate legitimacy. Because each brand page features its own distinct visual identity, pitch, and sign-in flow, the campaign effectively adapts to current news cycles and enterprise software adoption trends.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Island’s analysis indicates that these artificial intelligence advertising pages do not exist in a vacuum; rather, they form a critical component of a much broader, multi-pronged phishing operation. The same backend infrastructure also supports Google Ads-themed refund claims and payment confirmation portals, as well as fraudulent recruitment-related websites impersonating high-profile global entities such as Tesla, Louis Vuitton, Nike, and Adecco.

Technical analysis of the infrastructure reveals that all identified domains share a uniform technology stack built on Next.js and Socket.IO, maintaining constant communication with shared command-and-control endpoints. In a notable operational security lapse, the threat actors behind the platform inadvertently exposed the source code for earlier iterations of the phishing framework through misconfigured public GitHub repositories.

The primary objective of the artificial intelligence advertising campaign appears to be the systematic targeting of advertising agency staff, media buyers, and manager-account administrators. By compromising these accounts, the operators can monetize established advertising platforms either by running unauthorized ad campaigns using the victims’ budgets or by reselling the compromised accounts on underground markets, particularly those with a clean, established spend history.

This trend aligns with broader intelligence findings within the cybersecurity industry. A threat intelligence report published by Mimecast highlighted that malware families such as VietCredCare, DuckTail, NodeStealer, and PXA Stealer have significantly fueled ad account theft at scale. This has given rise to a widespread commodity crime wave across the digital advertising ecosystem, where malicious actors drain corporate budgets and traffic accounts with established trust ratings.

The consequences for compromised businesses can be severe and long-lasting. While financial losses associated with unauthorized credit card charges can often be remediated by removing payment methods within hours, recovering full administrative control of a compromised advertising account is significantly more difficult. Attackers routinely add their own administrative users while simultaneously downgrading the legitimate owners. Account recovery processes frequently take weeks or months, during which time the compromised infrastructure continues to serve unauthorized advertisements. In cases involving manager accounts, the operational damage extends outward to affect an entire agency’s client base.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

To mitigate these escalating threats, cybersecurity professionals recommend that organizations implement phishing-resistant authentication methods, maintain rigorous oversight of advertising control panel modifications, and subject all third-party artificial intelligence integrations to strict security vetting before connecting corporate accounts to external platforms.

This latest disclosure coincides with related findings from Island regarding threat actors abusing sponsored search results to route unsuspecting users toward custom GPTs or shared artificial intelligence chat content. These channels frequently redirect victims to fraudulent Cloudflare verification pages serving ClickFix-style lures designed to deliver payloads such as the NetSupport RAT.

Researchers emphasized that these campaigns do not rely on zero-day vulnerabilities within platforms like ChatGPT or Google. Instead, they exploit trusted digital platforms, attacker-authored content, paid search mechanisms, and advanced social engineering to guide users toward malware delivery and credential theft. Observational data collected across a three-month window highlights the scale of these interconnected threats, encompassing hundreds of paid-ad landing pages and numerous lookalike destinations designed to deceive enterprise users.

Leave a Reply

Your email address will not be published. Required fields are marked *