Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
Fake ChatGPT, Gemini, Claude, and Perplexity sites use browser-in-the-browser phishing to steal ad-account logins and MFA codes.
Island researchers reported a phishing campaign impersonating ChatGPT, Gemini, Claude, Perplexity, and Meta's Muse agent to target advertising account managers. A connect button opens a browser-in-the-browser fake Google window that collects credentials, while human operators request SMS or authenticator codes, Okta pushes, Google prompts, or QR codes. The same operation uses recruitment and refund lures, a shared Next.js and Socket.IO stack, and dozens of URLs. Misconfigured GitHub repositories traced it to March, and a Telegram channel received hundreds of victim submissions.