New Phishing Campaign Targets Ad Account Managers with Fake AI Tools
A sophisticated phishing campaign is exploiting fake versions of popular AI tools including ChatGPT, Gemini, Claude, and Perplexity to steal login credentials and multi-factor authentication (MFA) codes from ad account managers. The attack, discovered by researchers at browser security firm Island, leverages browser-in-the-browser (BitB) techniques to trick victims into entering sensitive information on fraudulent login pages.
How the Attack Works
The campaign capitalizes on the recent launch of Meta’s Muse AI agent, an assistant designed for personal tasks, to lure agency staff, media buyers, and administrators managing high-value ad accounts. Attackers use fake AI product pages promising tools for ad planning, auditing, and buyer targeting. When victims click the "Connect" button, a convincing but fake Google login window complete with a spoofed accounts.google.com URL appears within the original browser tab.
This BitB technique, first documented in 2022, creates a realistic-looking pop-up window using an iframe, mimicking legitimate OAuth prompts. The fake interface adapts to different operating systems (Windows, macOS, iOS, Android) and even supports dark mode. Once a victim enters credentials, a human operator takes control, requesting MFA codes (SMS, authenticator, or Okta push notifications) or repeatedly prompting for passwords to bypass security measures.
Broader Infrastructure & Impact
The campaign is part of a larger operation that also uses fake recruitment and refund pages, all sharing a common tech stack (Next.js, Socket.IO, Vercel frontends, and Railway/Render backends). Researchers traced the activity back to March 2024 after attackers exposed source code via misconfigured GitHub repositories.
The phishing platform supports sign-in workflows for Google, Meta, TikTok, and Okta, masking malicious traffic to appear as legitimate AI tool communications. While BitB attacks are deceptive, they can be detected unlike real browser windows, fake pop-ups cannot be moved outside the main window or resized.
Stolen Accounts & Criminal Exploitation
Compromised ad accounts are particularly valuable, as they often control ad spend budgets and access to downstream clients. Attackers either drain account balances through fraudulent ad campaigns or resell the credentials to other cybercriminals. A Telegram control channel linked to the operation had received hundreds of victim submissions, though the exact number of successful breaches remains unclear.
Researchers identified dozens of malicious URLs tied to the campaign, spanning ads, refunds, and recruitment lures. The full list of indicators is available in Island’s report.
Google TPRM report: https://www.rankiteo.com/company/googlellc
TikTok TPRM report: https://www.rankiteo.com/company/tiktokbusiness
"id": "gootik1791304073",
"linkid": "googlellc, tiktokbusiness",
"type": "Cyber Attack",
"date": "10/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 'Hundreds (estimated)',
'industry': 'Digital advertising, marketing',
'type': 'Ad agencies, media buyers, ad account '
'administrators'}],
'attack_vector': 'Browser-in-the-Browser (BitB) phishing, fake AI tool pages, '
'OAuth spoofing',
'data_breach': {'data_exfiltration': 'Credentials sold on dark web or used '
'for fraud',
'personally_identifiable_information': 'Yes (credentials, MFA '
'codes)',
'sensitivity_of_data': 'High (PII, financial access)',
'type_of_data_compromised': ['Login credentials',
'MFA codes',
'Ad account access']},
'date_detected': '2024-03',
'description': 'A sophisticated phishing campaign is exploiting fake versions '
'of popular AI tools including ChatGPT, Gemini, Claude, and '
'Perplexity to steal login credentials and multi-factor '
'authentication (MFA) codes from ad account managers. The '
'attack leverages browser-in-the-browser (BitB) techniques to '
'trick victims into entering sensitive information on '
'fraudulent login pages.',
'impact': {'brand_reputation_impact': 'Potential reputational damage for '
'affected ad agencies or platforms',
'data_compromised': 'Login credentials, MFA codes, ad account '
'access',
'financial_loss': 'Drained ad account balances through fraudulent '
'campaigns',
'identity_theft_risk': 'High (PII and credentials stolen)',
'operational_impact': 'Unauthorized access to ad accounts, '
'potential fraudulent ad spend',
'payment_information_risk': 'High (ad account budgets at risk)',
'revenue_loss': 'Potential loss from fraudulent ad spend or resale '
'of credentials',
'systems_affected': 'Ad account management platforms (Google, '
'Meta, TikTok, Okta)'},
'initial_access_broker': {'backdoors_established': 'Compromised ad accounts',
'data_sold_on_dark_web': 'Yes (credentials resold)',
'entry_point': 'Fake AI tool pages, '
'recruitment/refund lures',
'high_value_targets': 'Ad account managers, media '
'buyers'},
'investigation_status': 'Ongoing',
'lessons_learned': 'BitB phishing techniques are highly deceptive; MFA '
'fatigue can be exploited; misconfigured repositories can '
'expose attack infrastructure.',
'motivation': 'Financial gain, credential theft, resale of compromised ad '
'accounts',
'post_incident_analysis': {'corrective_actions': ['Enhance phishing awareness '
'training',
'Deploy phishing-resistant '
'MFA',
'Improve repository '
'security'],
'root_causes': ['Social engineering (fake AI '
'tools)',
'MFA fatigue',
'Misconfigured GitHub repositories '
'exposing attack infrastructure']},
'recommendations': ['Educate employees on BitB phishing risks',
'Implement phishing-resistant MFA (e.g., hardware tokens)',
'Monitor for suspicious OAuth prompts or unexpected MFA '
'requests',
'Audit GitHub/GitLab repositories for misconfigurations',
'Use browser security tools to detect BitB attacks'],
'references': [{'source': 'Island (browser security firm)'}],
'response': {'third_party_assistance': 'Island (browser security firm)'},
'title': 'New Phishing Campaign Targets Ad Account Managers with Fake AI '
'Tools',
'type': 'Phishing',
'vulnerability_exploited': 'Social engineering, MFA fatigue, misconfigured '
'GitHub repositories'}