Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity experts have uncovered details of a deceptive “human-operated phishing platform” that masquerades as advertising products for AI chatbots such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.

These products, which claim to provide campaign optimization, spend audits, and business-account connections, are crafted with the sole purpose of stealing credentials and multi-factor authentication (MFA) codes through spoofed login windows using the browser-in-the-browser (BitB) technique.

According to researchers Oleg Zaytsev and Ofek Ronen from Island, each product revolves around the action of “Connect,” which opens a browser within the real browser. The fake address bar displays trusted origins like accounts.google.com or an Okta tenant, while the phishing domain remains in the background.

The platform captures every password attempt, fingerprints the device, and allows an operator to select which MFA challenge the victim encounters next.

One of the implicated websites is “museads.ai,” which appeared shortly after Meta launched Muse, its AI agent for personal workflows. Described as “Your AI ads manager for paid media workflows,” the platform claims to assist users in reaching buyers, connecting their ad accounts, and running sponsored placements.

The deceptive webpage prominently features a Prompt Box with a “Connect” button, triggering a BitB attack to steal a visitor’s account credentials for Google, Meta, TikTok, and Okta workflows. This is achieved by displaying a fake window with a bogus account login form while the address bar points to a legitimate domain like accounts.google[.]com.

In the background, the victim’s device is fingerprinted, and the data is sent to the attacker at the endpoint “/api/send/ip” via Socket.IO. Subsequently, operator commands and victim data are exchanged for the login workflow, enabling the attacker to sign in to the account in real-time.

The researchers explain that each brand in the campaign offers a unique pitch, with ChatGPT promising a Monday Google Ads brief, Gemini providing MCC and linked-client support, Claude boasting its advertising portal, Perplexity offering campaign planning and spend audits, and Manus featuring a private Meta integration.

Users are directed to these deceptive landing pages through fake invitation emails impersonating trusted brands to add a semblance of legitimacy to the attacks.

Island reveals that the AI ads pages are part of a larger phishing platform supporting three main operations, including Google Ads-themed refund claims, payment confirmation, and recruitment-related sites for prominent brands like Tesla, Louis Vuitton, Nike, and Adecco.

All identified websites share the same technology stack of Next.js and Socket.IO and communicate with identical endpoints. Additionally, the threat actors have inadvertently exposed source code for earlier platform versions through misconfigured public GitHub repositories.

The AI ads-focused campaign targets agency staff, media buyers, and manager-account administrators, likely aiming to monetize ad accounts for personal gain.

To combat this threat, organizations are advised to implement phishing-resistant authentication, monitor advertising control changes, and carefully review AI integrations before connecting accounts.

The disclosure of this phishing campaign coincides with Island’s revelation of threat actors exploiting Google-sponsored results to lead unsuspecting users to deceptive GPTs or shared-AI chat content, ultimately redirecting them to a fraudulent Cloudflare verification page serving ClickFix-style lures to distribute NetSupport RAT.

This campaign leverages trusted platforms, attacker-created content, paid search, and social engineering to lure individuals towards malware delivery, underscoring the importance of remaining vigilant against such tactics in today’s cyber landscape.