Fake ChatGPT, Gemini and Other AI Sites Steal Ad Account Credentials and MFA Codes

Summary
Researchers uncovered a phishing campaign using fake AI sites and browser-in-the-browser login windows to steal advertising account credentials and MFA codes from agency staff, media buyers and administrators.
Key points
- The campaign impersonates ChatGPT, Gemini, Claude and Perplexity, using fake AI advertising tools to lure ad account managers into connecting their accounts.
- Fake Google login windows are built inside the phishing pages using iframes, making them appear to be legitimate sign-in pop-ups.
- Human operators can request passwords and SMS or authenticator codes, trigger approval prompts, or display QR codes during the phishing flow.
- Stolen ad accounts may let attackers spend available advertising balances on fraudulent campaigns or sell the accounts.
- Researchers linked the activity to a broader operation involving recruitment and refund lures; exposed source code in misconfigured public GitHub repositories helped trace it back to March.
- The campaign used dozens of URLs and a shared Next.js and Socket.IO stack; its Telegram control channel received hundreds of victim submissions, not necessarily confirmed account compromises.
- A fake login window cannot be moved outside or resized like a legitimate OAuth pop-up, which can help users identify this technique.
Article Details
- Attack Vectors
- Fake ChatGPT, Gemini, Claude, Perplexity, and Muse-related advertising pages prompt visitors to connect an account, then display a browser-in-the-browser window resembling a Google sign-in popup.
- The phishing platform locally recreates Google, Meta, TikTok, and Okta sign-in interfaces and collects credentials and MFA state through its own APIs.
- A human operator controls the phishing flow and may request repeated password entries, SMS or authenticator codes, approval prompts, or QR-code interaction.
- Island linked the advertising lures to a broader operation that also used fake recruitment opportunities and refund pages.
- Defensive Notes
- A browser-in-the-browser window cannot be moved outside its containing browser window or resized like a legitimate OAuth popup; Island identified these as ways to expose the deception.
MITRE ATT&CK
T1056.003 · Web Portal CaptureFake sign-in windows on the phishing pages collect victims' login credentials through locally recreated provider interfaces.T1111 · Multi-Factor Authentication InterceptionOperators request victims' SMS or authenticator codes during the phishing flow to get past MFA protections.
People
Vendors
GoogleHowever, the "connect" button opens a fake Google window inside the page, complete with an address bar showing accounts.google.com.MetaResearchers found that the phishing operation leveraged the recent launch of the Muse AI agent, which Meta describes as an assistant for various personal tasks.OktaThe attacker may ask for password entry up to three times, request an SMS or authenticator code to bypass MFA protections, display Okta push requests, show Google approval prompts, or display a QR code.TikTokIsland researchers found that the phishing platform supports Google, Meta, TikTok, and Okta sign-in workflows, and the commands are sent through Socket.IO events.
Products
ChatGPTFake ChatGPT, Gemini Sites steal advertising accounts, MFA codesClaudeA new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.GeminiFake ChatGPT, Gemini Sites steal advertising accounts, MFA codesMuseResearchers found that the phishing operation leveraged the recent launch of the Muse AI agent, which Meta describes as an assistant for various personal tasks.PerplexityA new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.