Fake AI Chatbot Ad Portals Hijack Credentials and MFA Codes
A sophisticated phishing platform is impersonating ad portals for popular AI chatbots like ChatGPT, Gemini, and Claude, aiming to steal user credentials and multi-factor authentication codes.

Cybersecurity researchers have uncovered a sophisticated human-operated phishing platform that meticulously impersonates advertising products for leading artificial intelligence (AI) chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. These fake platforms are designed to appear as legitimate tools for campaign optimization, spend audits, and business account connections, but their sole purpose is to capture sensitive user credentials and multi-factor authentication (MFA) codes.
The core of the attack relies on the "browser-in-the-browser" (BitB) technique. When a user clicks on a "Connect" button within these spoofed interfaces, a fake browser window is rendered inside the legitimate one. This fake window displays a convincing address bar, often mimicking trusted origins like accounts.google.com or Okta, while the actual phishing domain remains hidden. This visual deception aims to trick users into believing they are interacting with a secure, legitimate login portal.
Behind this deceptive interface, the platform actively captures every password attempt, fingerprints the victim's device, and allows an operator to select the specific MFA challenge the victim will face next. This level of control enables attackers to adapt their approach in real-time based on the information gathered. One example identified is "museads.ai," which emerged shortly after Meta launched its AI agent, Muse, and claimed to be an AI ads manager for paid media workflows.
The attackers tailor their pitches to each AI brand, promising features like Monday Google Ads briefs for ChatGPT users, MCC and linked-client support for Gemini, and dedicated advertising portals for Claude. These fake sites are often promoted through invitation emails that impersonate the trusted AI brands, further lending an air of legitimacy to the phishing attempts. The campaign demonstrates a keen awareness of current trends, adapting its lures to capitalize on the widespread adoption of AI tools.
Island, the research firm that disclosed these findings, noted that these AI ad pages are part of a larger phishing operation. This broader platform also includes lures related to Google Ads refund claims and payment confirmations, as well as fake recruitment sites for major brands like Tesla, Louis Vuitton, and Nike. All identified websites share a common technology stack, including Next.js and Socket.IO, and communicate with the same backend endpoints, indicating a centralized and organized operation.
The primary targets for this AI ads-focused campaign appear to be agency staff, media buyers, and manager-account administrators. The ultimate goal is likely the monetization of compromised ad accounts, either by running fraudulent ad campaigns or by selling these accounts on underground markets, especially those with a positive spending history. Such accounts are highly valuable due to their established reputation and credit lines.
Recovering compromised ad accounts can be a lengthy and arduous process for victims. Attackers often add their own administrators and downgrade the legitimate owner, making it difficult to regain control. This can lead to weeks or months of disruption, during which the account may continue to serve malicious ads, causing further damage to the business and its clients. To mitigate these risks, organizations are advised to enable phishing-resistant authentication, rigorously review advertising control changes, and carefully scrutinize any AI integrations before connecting accounts.
This campaign highlights a growing trend where threat actors leverage social engineering and trusted platforms rather than exploiting software vulnerabilities. By abusing paid search results and social media, attackers can effectively route unsuspecting users toward malicious content and malware delivery. The observed campaign involved hundreds of paid ad landings and numerous lookalike AI destinations, underscoring the scale and reach of this evolving threat landscape.