NEWS

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Island researchers disclosed a human-operated phishing platform impersonating ChatGPT, Gemini, and Claude ad portals to steal logins and MFA codes.

Dylan H.

News Desk

October 6, 2026
8 min read
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Fake AI Advertising Portals Built to Steal Logins and MFA Codes

Security researchers at Island have disclosed a "human-operated phishing platform" that impersonates advertising products from six major AI brands — Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus — to harvest advertiser credentials and multi-factor authentication (MFA) codes in real time. Researchers Oleg Zaytsev and Ofek Ronen found that every fake "product" funnels victims toward a single Connect button that opens a browser-in-the-browser (BitB) window spoofing legitimate sign-in pages such as accounts.google.com or an Okta tenant, while a human operator on the other end watches the session live and decides which MFA challenge to show next. The campaign has been active across 2025 and 2026, and researchers say victim submissions were still arriving through the operators' Telegram control channel as of publication on October 6, 2026. Google, Anthropic, OpenAI, Perplexity, and Meta are victims of brand impersonation in this campaign and were not involved in building or operating the phishing infrastructure.


Details

AttributeValue
Disclosed byIsland (researchers Oleg Zaytsev and Ofek Ronen)
Publication dateOctober 6, 2026
TechniqueBrowser-in-the-browser (BitB) phishing with human-operated MFA relay
Brands impersonatedGoogle Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, Manus
Example luremuseads.ai — fake Meta Muse Ads portal, registered September 16, 2026, eight days after Meta launched Muse
TargetsAgency staff, media buyers, and manager-account administrators for Google Ads, Meta, and TikTok
Platform stackNext.js front end plus Socket.IO real-time backend, reused across dozens of domains
Control channelTelegram, relaying operator commands alongside the Socket.IO session
AttributionNo specific threat actor, APT, or nation-state has been named; indicators point to financially motivated cybercriminals
Related luresSame backend reused for fake Google Ads refund scams and fake recruitment portals (Tesla, Louis Vuitton, Nike, Adecco branding)

How It Worked

The "Connect" button

Each fake product — a Gemini ads manager, a ChatGPT "Monday Brief," a Claude advertising portal, a Perplexity campaign planner, or Muse Ads — pitched a specific value proposition, such as campaign optimization, a free spend audit, or early access to a manager-account integration. Every pitch funneled the visitor toward one action: a Connect button. Clicking it did not open a new browser tab to a real identity provider. Instead, the page rendered a window drawn inside the existing browser tab — complete with a fake lock icon and an address bar reading accounts.google.com or an Okta tenant URL. The real browser's own outermost address bar never left the phishing domain, which is the one reliable tell for this technique: page content cannot spoof the browser's own window chrome.

A human watching every attempt

Behind that fake window, the platform ran as a stateful web application built on Next.js and Socket.IO, designed to mimic each identity provider's real login flow while quietly recording everything. The backend tracked multiple password attempts per victim, fingerprinted the device (IP address, approximate location, screen size, and WebGL data), and exposed operator-facing commands over the same socket connection — requesting a password retry, prompting for a specific MFA type (authenticator app, SMS code, or a Google/Okta push prompt), rejecting a code to force another attempt, or marking a session complete. A parallel Telegram channel mirrored these controls, letting a live operator steer each phishing session in real time rather than relying on a static credential-harvesting form.

Masked traffic, reused infrastructure

Because the platform locally rebuilt each provider's interface rather than proxying it, requests to the backend looked like ordinary application traffic between an AI product's front end and its own API, not like a classic reverse-proxy phishing kit relaying to a real login server. Researchers catalogued more than a hundred domains and backend endpoints tied to the operation, hosted on throwaway platforms such as Railway and Render, with naming patterns like chatgptadsback-production.up.railway.app and museadsback-production.up.railway.app repeating across brands. Misconfigured, publicly exposed GitHub repositories belonging to the operators also surfaced earlier versions of the same codebase, revealing that the identical state machine and three-password-retry logic had previously been reused for fake job-recruitment portals impersonating Tesla, Louis Vuitton, Nike, Adecco, and Google Careers.

What a successful "Connect" click hands over

A victim who completed the flow handed over not just a single password but a live, operator-verified session covering the advertiser's Google, Meta, or Okta identity — and, by extension, every ad account, manager account, and downstream client account reachable from it. Researchers noted the Telegram channel had logged hundreds of victim submissions at the time of disclosure, though that figure reflects form submissions rather than confirmed account takeovers.


Impact Assessment

Impact AreaDescription
Account takeoverCompromised identities give attackers access to Google Ads, Meta Business, and TikTok manager accounts, plus every client account reachable from them
Financial fraudStolen accounts with clean spend history and stored payment methods are reportedly resold on Telegram at two to four times the price of newly created accounts
MFA bypassReal-time operator control over which MFA prompt a victim sees defeats one-time codes and app-based approvals not cryptographically bound to the legitimate origin
Supply-chain exposureAgency and media-buyer accounts often control ad spend for multiple downstream clients, so one compromised login can expose numerous unrelated businesses
Brand abuseGoogle, Anthropic, OpenAI, Perplexity, and Meta are impersonated purely as lures; none of the affected vendors built or operated this infrastructure
Campaign reuseThe same Next.js/Socket.IO platform doubles as infrastructure for refund scams and recruitment-fraud lures, extending the blast radius beyond advertising accounts

Recommendations

For agencies and media buyers

  • Treat unsolicited "beta access," "free audit," or "manager account" invitations for AI advertising tools as unverified until confirmed on the vendor's official site — Google, Anthropic, OpenAI, Perplexity, and Meta did not launch the products referenced in this campaign.
  • Before entering a Google, Meta, or Okta login on any "Connect" prompt, check the browser's own outermost address bar and window chrome. A sign-in window rendered inside the page, rather than a genuine new OS-level browser window, is the giveaway for browser-in-the-browser attacks.
  • After connecting any third-party ad tool, review linked accounts for new managers, partners, or recovery-contact changes, and check for ad spend or campaigns nobody on the team approved.

For security teams

  • Adopt phishing-resistant authentication — origin-bound passkeys or hardware security keys — for any identity with access to advertising manager accounts; these methods cannot be relayed through a BitB overlay because the credential is cryptographically bound to the real origin.
  • Hunt proxy and DNS logs for indicators tied to this campaign: lookalike domains combining AI brand names with "ads," "beta," or "invite"; Socket.IO connections to Railway- or Render-hosted backends; and endpoints such as /api/send/ip or /api/create/user.
  • Flag internal reports of "wrong password, try again" loops or repeated unexpected MFA prompts on ad-platform logins as a potential indicator of a live, human-operated phishing session rather than user error.

For end users and job applicants

  • Apply the same scrutiny to recruitment sites as to ad-platform portals — the operators behind this campaign reused identical phishing infrastructure for fake job listings branded as Tesla, Louis Vuitton, Nike, Adecco, and Google Careers.
  • If you entered credentials or an MFA code into an AI advertising portal not hosted on the vendor's own domain, change that password immediately, revoke active sessions, and review connected-app and manager-account permissions on the real account.

Key Takeaways

  1. Island researchers Oleg Zaytsev and Ofek Ronen disclosed a human-operated phishing platform impersonating advertising products for Gemini, Claude, ChatGPT, Perplexity, Meta Muse, and Manus to steal credentials and MFA codes.
  2. The platform uses a browser-in-the-browser (BitB) technique — a fake login window drawn inside the real browser tab — so the visible address bar shows a trusted origin while the real browser stays on the phishing domain.
  3. A Next.js/Socket.IO backend lets a live human operator track password attempts, fingerprint devices, and choose which MFA challenge a victim sees, enabling real-time account takeover rather than static credential harvesting.
  4. Primary targets are agency staff, media buyers, and manager-account administrators, whose compromised identities can expose every downstream client account they can reach.
  5. No specific threat actor, APT, or nation-state has been attributed to this campaign; indicators — Telegram account resale, escrow services, and reuse for recruitment fraud — point to financially motivated cybercriminal operators.
  6. Phishing-resistant authentication (origin-bound passkeys or hardware security keys) is the most effective defense, since the credential cannot be relayed through a spoofed in-page browser window.

Sources