Cybersecurity researchers have uncovered a sophisticated, human-operated phishing platform specifically engineered to exploit the artificial intelligence boom. Threat actors are deploying a vast network of lookalike websites that impersonate advertising and workflow products for some of the world’s most prominent AI chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.

The campaign, detailed by researchers Oleg Zaytsev and Ofek Ronen from enterprise browser security firm Island, leverages the rapid integration of artificial intelligence into corporate workflows. By capitalizing on the trust organizations place in emerging AI marketing tools, the attackers have designed a seamless trap aimed directly at capturing credentials and multi-factor authentication (MFA) codes from media buyers, digital marketing agencies, and corporate administrators.

According to the researchers, each fake product centers around a singular, highly enticing action: the "Connect" button. When an unsuspecting visitor clicks this button on one of the fraudulent landing pages, it triggers a browser-in-the-browser (BitB) attack. This technique draws a convincing fake login window inside the victim’s real browser, displaying trusted origins such as genuine Google or Okta tenant address bars while the underlying browser remains isolated on the phishing domain.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Behind this polished interface, the platform performs comprehensive device fingerprinting, capturing every password attempt in real-time. Crucially, the platform operates as a human-driven mechanism, allowing a live operator to manually select which MFA challenge the victim encounters next. Armed with these harvested credentials and authentication bypasses, the threat actors attempt to compromise the targeted accounts instantly.

The timing and agility of the campaign underscore the adaptability of modern cybercrime syndicates. For instance, researchers identified a domain named "museads.ai," which materialized on September 16, 2026—just over a week after Meta launched Muse, its dedicated AI agent designed for personal workflows. Posing as an automated AI ads manager for paid media workflows, the spoofed site claimed to help users reach targeted buyers, connect their existing advertising accounts, and execute sponsored placements.

Prominently featured on the page was a prompt box equipped with the signature "Connect" button. Interacting with it initiated the BitB routine, conjuring a bogus sign-in form targeting Google, Meta, TikTok, and Okta workflows. Under the hood, the victim’s device information is immediately transmitted to the attacker’s infrastructure over Socket.IO via the endpoint "/api/send/ip," establishing a real-time communication channel where operator commands dictate the subsequent phases of the login workflow.

The threat actors have meticulously tailored their pitches to match the specific brand identities of each targeted AI ecosystem. ChatGPT-themed pages promise automated Monday Google Ads briefs, while Gemini-themed portals boast Manager Account (MCC) and linked-client support. Similarly, Claude is outfitted with a fictional advertising portal, Perplexity features campaign planning and spend audits, and Manus is leveraged through a purported private Meta integration.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

To drive traffic to these convincing portals, victims are reportedly directed via targeted phishing emails. These fraudulent messages impersonate trusted brands, lending the deceptive campaigns an initial veneer of legitimacy that convinces busy professionals to lower their guard. Island noted that these AI-focused pages are part of an even broader, multi-pronged phishing operation. The same infrastructure has been linked to Google Ads-themed refund claims, payment confirmation lures, and fake recruitment portals mimicking major global entities such as Tesla, Louis Vuitton, Nike, and Adecco.

Technical analysis of the infrastructure reveals a unified technology stack. All identified domains share a reliance on Next.js and Socket.IO, communicating with common backend endpoints. Furthermore, operational security lapses by the perpetrators—including misconfigured public GitHub repositories—have exposed the source code for earlier iterations of the phishing platform, giving researchers deep insight into its underlying architecture.

The primary motivation behind the AI ads campaign appears to be the large-scale monetization and exploitation of high-value advertising accounts. By targeting agency staff and manager-account administrators, the attackers aim to seize control of established accounts with clean spend histories. These compromised profiles can then be leveraged to run unauthorized ad campaigns or sold for profit on underground cybercrime markets.

This trend aligns with broader findings across the cybersecurity industry. A threat intelligence report published by Mimecast in July 2026 highlighted that specialized malware families—such as VietCredCare, DuckTail, NodeStealer, and PXA Stealer—have transformed ad account theft into a widespread commodity crime within the digital marketing ecosystem. Cybercriminals routinely drain corporate advertising budgets and trade mature accounts to bypass platform restrictions.

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

The consequences for victims extend far beyond immediate financial losses. While corporate credit cards linked to compromised accounts can often be canceled or cleared within hours, reclaiming the hijacked advertising accounts themselves presents a grueling challenge. Attackers typically elevate their own profiles to administrative status while downgrading the legitimate owners, leaving organizations locked out for weeks or months while their accounts continue to serve malicious advertisements. In cases involving agency manager accounts, the fallout extends directly to downstream clients.

Security experts advise organizations to deploy phishing-resistant authentication methods, such as hardware security keys, and to rigorously audit advertising control changes. Furthermore, enterprises are urged to scrutinize third-party AI integrations and software connections before granting them access to corporate accounts.

The disclosure of this phishing platform coincides with related findings from Island regarding how threat actors exploit trusted ecosystems. Recent investigations revealed that malicious actors have been abusing Google-sponsored search results to redirect users toward custom GPTs or shared AI chat content. These interactions ultimately steer victims toward fraudulent Cloudflare verification pages delivering NetSupport RAT via ClickFix-style social engineering lures.

Observational data covering a three-month period ending in August 2026 revealed that this broader delivery cluster encompassed approximately 850 paid-ad landing pages, 26 lookalike ChatGPT destinations, and 71 distinct Google Ads campaign IDs. Researchers emphasize that these campaigns do not rely on zero-day vulnerabilities in platforms like ChatGPT or Google, but rather exploit the inherent trust placed in mainstream applications, paid search visibility, and human psychology.

Leave a Reply

Your email address will not be published. Required fields are marked *