Fake ChatGPT, Gemini, Claude ad sites use browser-in-the-browser phishing to steal ad accounts and MFA codes
Island researchers disclosed a human-operated phishing platform using fake AI-brand advertising sites to steal advertising-account passwords and MFA codes via in-browser fake login windows.
Island researchers disclosed a human-operated phishing platform impersonating AI advertising products to steal advertising-account credentials and MFA codes. Sources differ on the brand list: BleepingComputer names ChatGPT, Gemini, Claude, Perplexity, and Meta's Muse; The Hacker News also lists Manus; GBHackers names ChatGPT, Claude, Gemini, and Muse; Cyber Security News says ChatGPT, Claude, Gemini, and other AI brands use lookalike advertising domains. A Connect button opens a browser-in-the-browser window spoofing sign-in pages — Google, Meta, TikTok, and Okta per BleepingComputer and The Hacker News, including trusted-looking origins such as accounts.google.com, while GBHackers specifically cites Google and Okta — while the real browser remains on the phishing site. Operators capture passwords (GBHackers: up to three password attempts stored), solicit MFA via SMS or authenticator codes, Okta pushes, Google prompts, or, per BleepingComputer, QR codes, and can reject submissions or select the victim's next MFA challenge. Targets include agency staff, media buyers, and advertising manager-account administrators; per GBHackers, stolen manager accounts can add admins, expose multiple clients, and divert ad spend. Cyber Security News reports the lures advertise ad accounts, invitations, and account sync, including ad portals, beta invites, and Google Ads MCC account sync. The pages share a Next.js and Socket.IO stack hosted, per BleepingComputer, on Vercel, Railway, or Render across dozens of URLs; GBHackers reports one Railway backend spanned 25 domains, and Cyber Security News says campaign backends on Railway and Render include hosts named for ChatGPT, Claude, and Gemini ad campaigns. The same stack also backs recruitment and Google Ads refund lures. BleepingComputer says misconfigured GitHub repositories trace the activity to March and that a Telegram channel received hundreds of victim submissions; GBHackers also reports hundreds of submissions. The Hacker News reports museads.ai appeared on 16 September 2026, just over a week after Meta launched Muse. The Hacker News separately describes a related cluster that used Google ads plus ClickFix pages to deliver NetSupport RAT, with about 850 paid-ad landings over three months ending August 2026.
- Island researchers disclosed the platform; reports published 2026-10-06 (BleepingComputer, The Hacker News) and 2026-10-07 (GBHackers, Cyber Security News).
- Impersonated brands differ by source: ChatGPT, Gemini, Claude, Perplexity, Meta Muse (BleepingComputer); plus Manus (The Hacker News); ChatGPT, Claude, Gemini, Muse (GBHackers); ChatGPT, Claude, Gemini, and other AI brands (Cyber Security…
- A Connect button opens a browser-in-the-browser window spoofing Google, Meta, TikTok, and Okta logins, including trusted-looking origins such as accounts.google.com.
- Operators capture passwords — up to three attempts stored, per GBHackers — and solicit SMS or authenticator codes, Okta pushes, Google prompts, or QR codes; they can reject submissions and choose the next MFA challenge.
- Targets are agency staff, media buyers, and advertising manager-account administrators; stolen manager accounts can add admins, expose multiple clients, and divert ad spend.
- Lures include ad portals, beta invitations, and Google Ads MCC account sync (Cyber Security News), plus recruitment and Google Ads refund sites on the same stack.
- Pages share a Next.js and Socket.IO stack hosted on Vercel, Railway, or Render across dozens of URLs; one Railway backend appeared across 25 domains, and hosts include ones named for ChatGPT, Claude, and Gemini ad campaigns.
- museads.ai appeared on 16 September 2026, just over a week after Meta launched Muse (The Hacker News).
Coverage timelineoldest first · each row is one article
- · 2d agoFake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
BleepingComputer· 74
Fake ChatGPT, Gemini, Claude, and Perplexity sites use browser-in-the-browser phishing to steal ad-account logins and MFA codes.
- · 2d agoFake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
The Hacker News· 67
A phishing platform spoofs AI ad portals for ChatGPT, Gemini, and Claude to steal credentials and MFA codes.
- · 1d ago