A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.
Researchers found that the phishing operation leveraged the recent launch of the Muse AI agent, which Meta describes as an assistant for various personal tasks.
The malicious pages target agency staff, media buyers, and administrators with accounts that extend to multiple downstream clients.
These accounts also typically allow attackers to spend available balances on fraudulent ad campaigns or resell them to other cybercriminals for significant amounts.
On the phishing sites, the fake AI products claim to help advertisers reach buyers, obtain ad briefs, and plan and audit advertising campaigns and spending.
To get the benefits, the user had to connect their account to the fake AI product. However, the “connect” button opens a fake Google window inside the page, complete with an address bar showing accounts.google.com.

Source: Island
BitB attacks
Browser-in-the-browser is a phishing technique devised by cybersecurity researcher mr. dox in March 2022 that consists of creating a fake browser window inside a legitimate one to display a fraudulent login page.
The fake window looks like a login pop-up, featuring realistic titles, interface, and the login URL expected by the user. But the fake window is just an iframe designed to steal the victim’s credentials.
The technique has been used extensively over the years, including for targeting Steam accounts.
Researchers at browser security company Island say that the attacker uses a kit that adapts the interface to Windows, macOS, iOS, and Android, including browser styling and dark-mode support.
Once the victim is in the BitB flow, a human operator takes over the process and controls what the victim is prompted to do next.
The attacker may ask for password entry up to three times, request an SMS or authenticator code to bypass MFA protections, display Okta push requests, show Google approval prompts, or display a QR code.
Operators can also reject codes submitted by the victims, hold them in a waiting screen, and finish or suppress the phishing flow at any time.

Source: Island
Broader campaign
By examining the infrastructure behind the campaign, the researchers found that the campaign is part of a larger operation that used multiple lures, such as fake recruitment opportunities and refund pages.
All pages tied to the same operation share a Next.js and Socket.IO stack, common API endpoints, and many use Vercel frontends with Railway or Render backends.

Source: Island
The connection to the larger operation was possible because the attacker exposed older source code through misconfigured public GitHub repositories, allowing the activity to be traced as far back as March.
The researchers have also found that the Telegram control channel used in the attacks had received hundreds of victim submissions, although that figure does not necessarily reflect the number of successfully compromised accounts.
BitB attacks are deceptive but also easy to uncover, since iframes cannot be moved outside the browser window or resized, unlike a legitimate OAuth popup
These are simple actions supported by real browser windows, but impossible to perform in BitB windows.
Island researchers found that the phishing platform supports Google, Meta, TikTok, and Okta sign-in workflows, and the commands are sent through Socket.IO events.
“Unlike a transparent reverse-proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs,” the researchers say in a report today.
This masks the traffic, making it appear to be coming from an AI product communicating with an unrelated application backend.
Based on the researchers’ findings, the phishing operation used dozens of URLs for campaigns focused on ads, refunds, and recruitment. The report includes a list of all URLs associated with this activity.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

