"The Telegram control channel used in the attacks had received hundreds of victim submissions," researchers report — a concrete tally that underscores how a modern phishing kit is weaponizing generative-AI branding to steal advertising accounts and even multi‑factor authentication (MFA) codes.
Browser‑in‑the‑browser (BitB): the technical pivot
At the heart of the campaign is a phishing technique known as browser‑in‑the‑browser, or BitB, a deception first devised by cybersecurity researcher mr. dox in March 2022. BitB creates a fake browser window inside a legitimate one — typically an iframe — that displays a convincingly real login prompt, including the expected URL and interface elements. Because the fake window is actually inside the page, it cannot be moved outside the browser window or resized, unlike a legitimate OAuth popup; that difference is one of the telltale signs Island researchers point to when uncovering attacks.
In this campaign the BitB flow is not purely automated. Once a potential victim enters the flow, a human operator takes over, controlling what prompts the victim sees next. Operators can ask for passwords multiple times, request SMS or authenticator codes, surface Okta push approvals, show Google approval prompts or QR codes, and are able to reject codes, hold victims on a waiting screen, or terminate the phishing flow at will.
Fake ChatGPT, Gemini, Claude, Perplexity — and the Muse AI lure
The malicious pages impersonate major AI products — including sites built to resemble ChatGPT, Gemini, Claude, and Perplexity — and explicitly leaned on the recent launch of Meta’s Muse AI agent as a topical lure. The fraudulent storefronts promise tools that will help advertisers “reach buyers,” obtain ad briefs, and plan and audit advertising campaigns and spending. To deliver those benefits, the pages prompt victims to “connect” their accounts; the connect button opens a fake Google window inside the page, complete with an address bar showing accounts.google.com.
Island’s analysis shows the campaign deliberately targets agency staff, media buyers, and administrators who manage advertising accounts that extend to multiple downstream clients — accounts that can be used to run fraudulent ad campaigns or resell as valuable assets to other criminals. The Telegram control channel used by the attackers had logged hundreds of victim submissions, the researchers say, though that number does not necessarily equal successful compromises.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageShared infrastructure: Next.js, Socket.IO, Vercel, and exposed code
Researchers traced the operation’s infrastructure and found a consistent technology footprint: many pages tied to the operation share a Next.js and Socket.IO stack, common API endpoints, and frequently use Vercel frontends with Railway or Render backends. The connection across campaigns was further revealed when older source code was exposed in misconfigured public GitHub repositories, allowing tracing back to activity as early as March.
Island reports that the platform supports sign‑in workflows for Google, Meta, TikTok, and Okta, and that the phishing commands are relayed via Socket.IO events. As Island puts it in their report today: "Unlike a transparent reverse‑proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs." That rebuilding masks the traffic, making it appear to originate from an AI product communicating with an unrelated backend.
Why the campaign is both detectable and stealthy
BitB attacks are deceptive but not invisible. The iframe nature of the fake popup prevents it from being moved or resized — actions users can perform with genuine OAuth popups — and investigators can use those constraints to identify fraud. Yet the operation’s approach of locally rebuilding identity provider interfaces and routing commands through Socket.IO makes the interaction look legitimate at the application layer, complicating automated detection and forensic attribution.
What this means for technologists, agency staff, and platform operators
- Technologists and security teams: Island’s findings show the value of instrumenting UI behavior checks — for example, detecting iframe constraints and verifying the origin of OAuth windows — and monitoring unusual Socket.IO activity tied to authentication flows.
- Agency staff, media buyers, and administrators: Because the campaign targets accounts that control funds and multiple client relationships, those roles should treat unsolicited AI‑branded tools that ask to “connect” ad accounts as high‑risk and verify authenticity through established vendor channels before granting access.
- Platform operators (Google, Meta, TikTok, Okta): The campaign leverages rebuilt sign‑in interfaces and approval prompts. Providers will need to consider UI hardening and signaling methods that make genuine popups and approval workflows harder to spoof at the page level.
Island’s report includes a list of dozens of URLs associated with the operation and documents the shared code and control channels the attackers used. The adversary’s combination of topical AI branding, interactive BitB popups, and a human‑operated backend turned what might have been a routine credential harvest into an adaptable fraud factory that specifically targets the high-value ecosystem of advertising accounts. With public GitHub misconfigurations exposing older code and a Telegram feed collecting victim submissions, the operation left investigators a trail — and left affected organizations a pointed set of remedies to prioritize.




