Skip to main content
Emerging Threats

Phishing Sites Impersonate AI Chatbots to Capture Credentials

Person sitting in coffee shop with laptop showing blurred login page.

"Each product was built around the same action: Connect," Island researchers Oleg Zaytsev and Ofek Ronen wrote — a line that cuts to the heart of a coordinated phishing effort that impersonates advertising products for ChatGPT, Gemini, Claude, Perplexity, Meta Muse, Manus and others to harvest credentials and multi-factor authentication (MFA) codes.

How the browser-in-the-browser trick stole logins in real time

Researchers who examined the campaign describe a human-operated phishing platform that uses the browser-in-the-browser (BitB) technique to present spoofed sign-in windows inside a real browser. The fake address bar displayed trusted origins — examples include accounts.google[.]com or an Okta tenant — while the actual browser remained on the phishing domain. Behind that façade, the platform recorded every password attempt, fingerprinted the device, and allowed an operator to select which MFA challenge the victim would see next. Captured credentials were then used in real time as the attacker attempted to sign in to the targeted account.

Fake AI ad portals and the museads.ai example

One of the landing pages, museads.ai, appeared on September 16, 2026 and marketed itself as "Your AI ads manager for paid media workflows." Island said the campaign presented bespoke pages for multiple brands — ChatGPT offering a Monday Google Ads brief, Gemini promising MCC and linked-client support, Claude presenting an advertising portal, Perplexity offering campaign planning and spend audits, and Manus advertising a private Meta integration — all with a prominent "Connect" button that triggered the BitB capture flow.

Shared infrastructure, exposed source, and delivery pathways

Island reported that all identified sites shared the same Next.js and Socket.IO technology stack and communicated with common endpoints. The platform sent fingerprint and connection data to an endpoint at "/api/send/ip" over Socket.IO, then exchanged operator commands and victim data according to the login workflow. Researchers also found earlier versions of the platform's source code exposed through misconfigured public GitHub repositories.

Island further said the campaign did not rely on a vulnerability in AI chat services themselves; rather, threat actors abused paid search, trusted platforms, attacker-authored content, and social engineering. Over a three-month observation period ending in August 2026, the broader delivery cluster included roughly 850 paid-ad landings, 26 lookalike ChatGPT destinations, and 71 Google Ads campaign IDs.

Three-pronged operation and connected abuse of search and chat

The AI-ads pages are one component of a broader, three-pronged phishing platform described by Island. The other two prongs included Google Ads-themed refund claims and payment-confirmation pages, plus recruitment-related sites impersonating Tesla, Louis Vuitton, Nike, and Adecco. Island also reported abuse of Google-sponsored results to route victims to custom GPTs or shared-AI chat content that redirected users to a fake Cloudflare verification page; those pages then served ClickFix-style lures to deliver NetSupport RAT.

Ad-account theft, malware families, and recovery pain

Island tied the AI ads campaign to a known pattern of ad-account monetization and theft. The attackers appear focused on agency staff, media buyers, and manager-account administrators — profiles that allow adversaries to run ads from hijacked accounts or to sell accounts with clean spend histories. Mimecast's July 2026 report cited malware families such as VietCredCare, DuckTail, NodeStealer, and PXA Stealer as contributors to large-scale ad account theft. Island noted bluntly: "For the victim, the card is the easy part: they can remove it within hours. Getting the account back is not," adding that attackers typically add administrators and downgrade the legitimate owner, making recovery a process that can take weeks or months while the account continues to serve ads.

What this means for technologists, advertisers, and enterprise owners

  • Technologists and security teams: The researchers recommend enabling phishing-resistant authentication and reviewing advertising control changes. The platform's reuse of a common stack and exposed source on GitHub are concrete forensic signals to hunt for in telemetry and web logs.
  • Advertisers, agencies, and media buyers: Pages mimicking ad-management tools — and invitation emails impersonating trusted brands — are designed to look like platform integrations. Organizations are advised to scrutinize AI integrations before connecting accounts and to monitor manager-account administrator additions and spend patterns closely.
  • End users and account holders: Because the campaign captures MFA flows and fingerprints devices, removing a payment card is often only the first step; account restoration can be prolonged if attackers have already added administrators or altered controls. Watch for unexpected sign-in flows and verify invitations through known vendor channels before clicking Connect.

The operation Island describes is notable for its operational polish: bespoke landing pages matched to current product launches, live operator control of MFA presentation, and broad use of paid search and lookalike chat destinations to route victims. At the same time, the investigators found repeatable technical indicators — shared endpoints, a common tech stack, and exposed source code — that defenders can use to detect and disrupt the platform.

Read the original Island disclosure at The Hacker News: https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html