Fake AI sites used in phishing campaign targeting advertising accounts, MFA codes

Browser-in-browser attack mimics ChatGPT, Gemini, and other AI tools to steal credentials

By LineZotpaper
Published
Read Time2 min
A new phishing campaign is using fake websites mimicking popular AI tools such as ChatGPT, Gemini, Claude, and Perplexity to steal login credentials and multi-factor authentication codes from advertising account managers, according to researchers at browser security company Island.

The campaign targets agency staff, media buyers, and administrators whose accounts extend to multiple downstream clients. Once compromised, attackers can spend available balances on fraudulent ad campaigns or resell the accounts for significant sums.

The phishing pages claim to offer AI-powered advertising assistance, but clicking the "connect" button opens a fake Google login window inside the page using the browser-in-the-browser (BitB) technique. The fake window displays a realistic address bar showing accounts.google.com.

Researchers found that a human operator takes over the process after the victim enters the BitB flow. The operator may request password entry up to three times, ask for an SMS or authenticator code to bypass MFA protections, display Okta push requests, show Google approval prompts, or display a QR code. Operators can reject submitted codes, hold victims on a waiting screen, or end the phishing flow at any time.

The campaign leverages the recent launch of Meta's Muse AI agent as a lure. By examining the infrastructure, researchers discovered that the operation is part of a larger campaign using multiple lures such as fake recruitment opportunities and refund pages. All pages share a common technology stack: Next.js and Socket.IO, with Vercel frontends and Railway or Render backends.

The browser-in-the-browser technique was originally devised by cybersecurity researcher mr. dox in March 2022 and has been used previously to target Steam accounts. Island's researchers noted that the attack kit adapts the interface to Windows, macOS, iOS, and Android, including browser styling and dark-mode support.

§

Analysis

Why This Matters

  • Ad account managers risk losing control of client budgets if their credentials are stolen, potentially leading to significant financial losses and reputational damage.
  • The ability to bypass MFA through human-in-the-loop attacks highlights a critical gap in current authentication protections.
  • The campaign demonstrates sophisticated targeting of specific roles within the advertising industry, suggesting attackers have done their research.

Background

Phishing tactics have evolved from simple email links to advanced techniques like browser-in-the-browser attacks, where a fake browser window is rendered inside a legitimate one to steal credentials. This campaign combines that technique with real-time human operators who can adapt to MFA challenges. The use of AI brand names is a common social engineering tactic that capitalises on public interest in tools like ChatGPT and Gemini.

Key Perspectives

Ad account managers and agency staff: They face a heightened threat as attackers specifically target their credentials. Vigilance is required when connecting third-party services to social media accounts, especially when prompted with a login window that looks legitimate.

Security researchers: The campaign underlines the need for organisations to implement phishing-resistant MFA, such as hardware security keys, and to train employees to recognise fake browser windows and unusual login prompts.

Attackers: They see advertising accounts as valuable assets that can be exploited for fraudulent ad spend or resold on underground markets. The campaign's use of a sophisticated tech stack and human operators increases its chances of success.

What to Watch

  • Increased reports of stolen advertising accounts being resold or used for fraudulent campaigns.
  • Further phishing campaigns using the same infrastructure or targeting other social media and advertising platforms.
  • Responses from Meta, Google, and other companies to block or takedown the phishing domains and warn users.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.