Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Cybersecurity researchers have disclosed details of a that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.

The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain." "Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next." One of the websites in question is "museads.ai," which emerged on September 16, 2026, a little over a week after Meta launched Muse , its AI agent designed for personal workflows.
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.
The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in mind: to capture credentials and multi-factor authentication (MFA) codes via spoofed login windows using the browser-in-the-browser ( BitB ) trick.
Prominently placed in the spoofed web page is a Prompt Box with a "Connect" button, clicking which triggers a BitB attack to capture a visitor's account credentials for Google, Meta, TikTok, and Okta workflows.
More recently, threat actors accessed another employee's Microsoft 365 account in September and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees.
In the background, the victim's device is fingerprinted, and the information is transmitted to the attacker at the endpoint "/api/send/ip" over Socket.IO, after which operator commands and victim data are exchanged based on the login workflow.
According to a report published by Mimecast in July 2026, malware families like VietCredCare, DuckTail, NodeStealer, and PXA Stealer have engendered ad account theft at scale, leading to a "widespread commodity crime in the advertising ecosystem" where bad actors drain business budgets and sell accounts with good reputation in underground markets.
Island researchers found that the phishing platform supports Google, Meta, TikTok, and Okta sign-in workflows, and the commands are sent through Socket.IO events.
New RemControl Android banking malware targets users in Europe and Canada BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
What happened
The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain." "Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next." One of the websites in question is "museads.ai," which emerged on September 16, 2026, a little over a week after Meta launched Muse , its AI agent designed for personal workflows.
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.
What changed
Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.
The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in mind: to capture credentials and multi-factor authentication (MFA) codes via spoofed login windows using the browser-in-the-browser ( BitB ) trick.
Who is affected
Prominently placed in the spoofed web page is a Prompt Box with a "Connect" button, clicking which triggers a BitB attack to capture a visitor's account credentials for Google, Meta, TikTok, and Okta workflows.
More recently, threat actors accessed another employee's Microsoft 365 account in September and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees.
Why it matters
In the background, the victim's device is fingerprinted, and the information is transmitted to the attacker at the endpoint "/api/send/ip" over Socket.IO, after which operator commands and victim data are exchanged based on the login workflow.
According to a report published by Mimecast in July 2026, malware families like VietCredCare, DuckTail, NodeStealer, and PXA Stealer have engendered ad account theft at scale, leading to a "widespread commodity crime in the advertising ecosystem" where bad actors drain business budgets and sell accounts with good reputation in underground markets.
Technical details
Island researchers found that the phishing platform supports Google, Meta, TikTok, and Okta sign-in workflows, and the commands are sent through Socket.IO events.
New RemControl Android banking malware targets users in Europe and Canada BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
For a manager account, the damage reaches the agency’s clients." To mitigate the threat, organizations are recommended to enable phishing-resistant authentication, review advertising control changes, and scrutinize AI integrations before connecting accounts.
Response
Later on October 6, ASOS said it was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities." At this stage, the company acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.
The disclosure comes as Island revealed that threat actors are abusing Google-sponsored results to route unsuspecting users to custom GPTs or shared-AI chat content , which then redirect them to a fake Cloudflare verification page serving ClickFix-style lures to deliver NetSupport RAT.
What remains unknown
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails.
Districts need to understand why access through that application exposed sensitive employee records and whether similar access paths remain elsewhere in the environment.” Thus far, it’s unclear how many districts and staff members are impacted by the breach.
Attribution
The Hacker News: Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus.
BleepingComputer: A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks.
Infosecurity Magazine: Microsoft Threat Intelligence described the technique in a post on X on October 3 , saying a cluster of compromised websites was leading visitors to the attacks.
Infosecurity Magazine: In a statement published October 4 , the company said an employee's Google Workspace account had been accessed from outside since late July, potentially exposing the names and email addresses of 1646 employees, business partners and others.