Sophisticated Human-Operated Phishing Platform Weaponizes Popular AI Chatbots to Steal Enterprise Credentials

Cybersecurity researchers have uncovered a sophisticated, human-operated phishing platform that weaponizes the growing popularity of generative artificial intelligence by impersonating advertising and management products associated with major AI chatbots. The campaign leverages trusted brands like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus to trick corporate workers, digital agencies, and media buyers into handing over critical credentials and multi-factor authentication codes.

According to a detailed report shared by researchers Oleg Zaytsev and Ofek Ronen from enterprise browser security firm Island, the fraudulent campaign is built around deceptive tools that promise businesses advanced marketing capabilities. These spoofed products claim to offer essential services such as campaign optimization, advertising spend audits, and seamless business-account integrations. Behind these polished user interfaces, however, lies an aggressive infrastructure designed to capture user authentication data in real-time through advanced browser-in-the-browser techniques.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

The operation gained immediate traction by swiftly capitalizing on industry news and new product rollouts. For instance, researchers identified a fraudulent website operating under the domain "museads.ai," which abruptly emerged on September 16, 2026—just a little over a week after Meta officially launched Muse, its personal AI agent designed for specialized workflows. The malicious site pitched itself as an advanced AI ads manager tailored for paid media workflows, enticing prospective users with the promise of reaching buyers, connecting existing ad accounts, and effortlessly managing sponsored placements.

Prominently featured on these deceptive web pages is a prompt box complete with a "Connect" button. When an unsuspecting visitor clicks this button, it triggers a browser-in-the-browser attack. Instead of directing the user to an authentic sign-in page, the script draws a fake window displaying a bogus account authentication form. While the spoofed address bar displays trusted origins such as accounts.google.com or an authorized Okta tenant, the underlying browser remains firmly anchored to the malicious phishing domain.

As explained by the Island researchers, every product within this sprawling campaign was meticulously structured around a single, universal action: connecting an account. Each brand was given a customized pitch tailored to its perceived user base and functional ecosystem. ChatGPT promised Monday Google Ads briefs, Gemini offered manager account and linked-client support, Claude featured its own dedicated advertising portal, Perplexity advertised comprehensive campaign planning and spend audits, and Manus provided a seamless integration with Meta. Users were typically lured to these landing pages through sophisticated phishing emails disguised as official beta invitations or compliance updates from these trusted brands.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

While the victim interacts with the fake login interface, the underlying platform performs deep device fingerprinting. This telemetry data is immediately transmitted to the attacker at a specific endpoint over Socket.IO, enabling human operators to monitor the interaction and decide which multi-factor authentication challenge the victim should encounter next. Armed with the harvested credentials and real-time MFA tokens, the threat actors attempt to compromise the targeted corporate accounts instantaneously.

The broader implications of this campaign extend far beyond simple credential harvesting. Island revealed that the AI advertising pages are merely one component of a much larger, multi-pronged phishing platform. The infrastructure also supports Google Ads-themed refund claims and payment confirmations, alongside elaborate recruitment portals impersonating high-profile global brands such as Tesla, Louis Vuitton, Nike, and Adecco. Technical analysis of the underlying architecture revealed that all identified websites share a unified technology stack powered by Next.js and Socket.IO, communicating with common operational endpoints. In a notable operational security lapse, the threat actors inadvertently exposed the source code for earlier iterations of the platform through misconfigured, publicly accessible GitHub repositories.

The primary objective behind the AI-focused phishing campaign appears to be the large-scale compromise of agency staff, digital media buyers, and manager-account administrators. By seizing control of established advertising accounts, particularly those with a clean historical spend and a strong reputation, threat actors can weaponize corporate budgets to launch unauthorized ad campaigns or monetize the compromised assets on underground markets.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

This trend mirrors broader developments across the cybersecurity landscape. A threat intelligence report published by Mimecast highlighted that ad account theft has evolved into a widespread commodity crime within the digital marketing ecosystem. Malicious actors frequently leverage specialized stealer malware to drain corporate advertising budgets and trade high-value accounts. Once attackers gain administrative control, recovery is notoriously difficult. They typically elevate their own rogue accounts, downgrade the legitimate owner, and lock out corporate security teams while the stolen accounts continue to serve unauthorized ads, eventually inflicting severe reputational and financial damage on both the primary agency and its corporate clients.

Security experts emphasize that mitigating this complex threat requires a multi-layered defensive posture. Organizations are strongly advised to deploy phishing-resistant authentication methods, continuously monitor advertising console and permission changes, and subject any third-party AI integrations or browser extensions to rigorous security scrutiny before granting them access to core enterprise accounts.

The disclosure of this human-operated platform coincides with related findings from Island regarding how threat actors exploit trusted digital pathways. Security researchers recently documented separate campaigns where adversaries abused Google-sponsored search results to direct unsuspecting users toward custom GPT repositories or shared AI chat content. These channels subsequently routed victims to fraudulent Cloudflare verification pages serving ClickFix-style social engineering lures designed to drop the NetSupport RAT malware. As cybercriminals continue to blend generative AI terminology with traditional social engineering and paid search abuse, organizations must remain vigilant against the evolving convergence of artificial intelligence and enterprise cyber threats.

Leave a Reply

Your email address will not be published. Required fields are marked *