Fake ChatGPT, Gemini and Other AI Sites Steal Ad Account Credentials and MFA Codes

· Original article ↗

Summary

Researchers uncovered a phishing campaign using fake AI sites and browser-in-the-browser login windows to steal advertising account credentials and MFA codes from agency staff, media buyers and administrators.

Key points

  • The campaign impersonates ChatGPT, Gemini, Claude and Perplexity, using fake AI advertising tools to lure ad account managers into connecting their accounts.
  • Fake Google login windows are built inside the phishing pages using iframes, making them appear to be legitimate sign-in pop-ups.
  • Human operators can request passwords and SMS or authenticator codes, trigger approval prompts, or display QR codes during the phishing flow.
  • Stolen ad accounts may let attackers spend available advertising balances on fraudulent campaigns or sell the accounts.
  • Researchers linked the activity to a broader operation involving recruitment and refund lures; exposed source code in misconfigured public GitHub repositories helped trace it back to March.
  • The campaign used dozens of URLs and a shared Next.js and Socket.IO stack; its Telegram control channel received hundreds of victim submissions, not necessarily confirmed account compromises.
  • A fake login window cannot be moved outside or resized like a legitimate OAuth pop-up, which can help users identify this technique.

Article Details

Attack Vectors
  • Fake ChatGPT, Gemini, Claude, Perplexity, and Muse-related advertising pages prompt visitors to connect an account, then display a browser-in-the-browser window resembling a Google sign-in popup.
  • The phishing platform locally recreates Google, Meta, TikTok, and Okta sign-in interfaces and collects credentials and MFA state through its own APIs.
  • A human operator controls the phishing flow and may request repeated password entries, SMS or authenticator codes, approval prompts, or QR-code interaction.
  • Island linked the advertising lures to a broader operation that also used fake recruitment opportunities and refund pages.
Defensive Notes
  • A browser-in-the-browser window cannot be moved outside its containing browser window or resized like a legitimate OAuth popup; Island identified these as ways to expose the deception.

MITRE ATT&CK

People

Vendors

Products

Industries

Related Articles