Cybersecurity researchers have uncovered a sophisticated, human-operated phishing campaign that deploys highly convincing fake advertising products tailored for prominent artificial intelligence chatbots. The operation meticulously impersonates marketing and workflow management tools for major AI platforms including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus, aiming to harvest corporate credentials and multi-factor authentication (MFA) codes.

According to a detailed technical report published by Island researchers Oleg Zaytsev and Ofek Ronen, these fraudulent platforms are engineered to lure marketing agencies, media buyers, and enterprise account administrators. By promising cutting-edge features such as campaign optimization, automated spend audits, and seamless business-account integrations, the threat actors establish an initial veneer of legitimacy to compromise high-value accounts.

The infrastructure behind these attacks relies on a unified technical blueprint. Every fake product showcased across the campaign is built around a single primary action: a prominent "Connect" button. When an unsuspecting victim clicks this interface, the platform initiates a browser-in-the-browser (BitB) attack. Instead of redirecting the user away from the page, the application draws a sophisticated fake browser window directly inside the actual browser interface.

This spoofed window displays trusted, recognizable domain origins—such as accounts.google.com or legitimate Okta authentication tenants—while the underlying browser safely remains on the malicious phishing domain. Behind this deceptive user interface, the platform actively fingerprints the victim’s hardware and software configuration while logging every attempted password keystroke. Furthermore, the architecture features real-time human operator controls, allowing a live attacker to dynamically select which MFA challenge the victim encounters next based on the ongoing login workflow.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

The agility of the operation is demonstrated by how quickly the threat actors adapt to industry news. For instance, following Meta’s launch of Muse—an AI agent designed for personal workflows—a fraudulent landing page titled "museads.ai" emerged just over a week later on September 16, 2026. This spoofed portal marketed itself as an AI advertising manager capable of connecting ad accounts and executing sponsored placements. The page prominently featured a prompt box with a "Connect" button, which instantly triggered a BitB attack to harvest account credentials across Google, Meta, TikTok, and Okta workflows.

Once a target initiates the login process, the background application captures the device fingerprint and transmits it directly to the attacker’s endpoint at /api/send/ip utilizing Socket.IO. This real-time communication channel allows the human operator to orchestrate the downstream login workflow and immediately test the harvested credentials against the legitimate services.

The customization of these fraudulent portals extends across the entire ecosystem of major generative AI tools. The researchers noted that each brand features a tailored pitch designed to appeal to specific professional use cases. ChatGPT-themed pages promise automated Monday advertising briefs for Google Ads, while Gemini-themed portals boast Manager Account (MCC) and linked-client support. Similarly, Claude features a dedicated advertising portal interface, Perplexity offers comprehensive campaign planning and spend audits, and Manus lures victims with a specialized private Meta integration.

Targets are typically driven to these landing pages through carefully crafted phishing and invitation emails designed to mimic official beta programs and product updates from trusted technology brands. These messages lend the fraudulent ecosystem an additional layer of credibility, enabling the campaign to successfully target professionals who routinely adopt new technological tools for their daily business operations.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Island’s analysis reveals that these AI advertising portals represent just one component of a much broader, modular phishing platform. The underlying infrastructure also supports two other distinct operational pillars: Google Ads-themed refund claims and payment confirmation portals, alongside fraudulent recruitment websites impersonating prominent global brands and agencies such as Tesla, Louis Vuitton, Nike, and Adecco.

Technical analysis of the infrastructure indicates that all identified malicious websites share a uniform technology stack built on Next.js and Socket.IO, communicating with a centralized set of command-and-control endpoints. Accidental exposure has further illuminated the inner workings of the threat group, as earlier versions of the platform’s source code were inadvertently left accessible through misconfigured public GitHub repositories.

The primary objective behind the AI-focused advertising campaign is the large-scale monetization of corporate advertising accounts. By targeting media buyers, agency staff, and enterprise account administrators, the threat actors seek to gain control over established accounts with clean spend histories. These hijacked accounts can subsequently be leveraged to run unauthorized malicious advertising campaigns or sold for profit on underground cybercrime markets.

This trend aligns with broader findings across the cybersecurity industry. In July 2026, a threat intelligence report published by Mimecast highlighted how specialized malware families—such as VietCredCare, DuckTail, NodeStealer, and PXA Stealer—have driven a dramatic surge in ad account theft across the digital marketing ecosystem. Cybercriminals frequently drain existing business budgets and trade high-reputation accounts to bypass platform security restrictions.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

The consequences of a successful compromise can be severe and long-lasting for organizations. While recovering a stolen credit card linked to an advertising account is relatively straightforward, regaining control of the underlying account presents a significant challenge. Threat actors routinely inject their own administrative accounts, demote legitimate owners, and lock out the original staff. Recovery processes can span weeks or months, during which time the compromised account continues to accrue unauthorized advertising charges. In scenarios involving agency manager accounts, the operational damage extends directly to the agency’s downstream clients.

To defend against these emerging threats, cybersecurity experts recommend that organizations implement phishing-resistant authentication methods, continuously monitor advertising infrastructure for unauthorized control changes, and thoroughly vet third-party AI integrations before connecting them to corporate enterprise accounts.

The disclosure of this phishing platform coincides with related findings from Island regarding how threat actors exploit trusted discovery channels. Recently, researchers revealed that malicious actors have been abusing Google-sponsored search results to direct unsuspecting users toward custom GPTs or shared AI chat content. These auxiliary channels subsequently redirect victims to fraudulent Cloudflare verification pages utilizing ClickFix-style social engineering lures to deliver the NetSupport Remote Access Trojan (RAT).

Rather than exploiting vulnerabilities in foundational AI platforms like ChatGPT or Google’s search algorithms, these campaigns rely on the systematic abuse of trusted platforms, attacker-authored content, paid advertising networks, and advanced social engineering. Observational data collected across a three-month period ending in August 2026 underscores the scale of these operations, encompassing approximately 850 paid-ad landing pages, 26 lookalike ChatGPT destinations, and 71 distinct Google Ads campaign IDs utilized in broader malware delivery clusters.

Leave a Reply

Your email address will not be published. Required fields are marked *