AI-Branded Lures Target the People Who Control Ad Budgets
A phishing operation is impersonating ChatGPT, Gemini, Claude, and Perplexity to target advertising account managers, media buyers, and ad administrators — roles that typically hold spending authority across multiple client accounts. The campaign combines convincing AI-tool branding with a technically sophisticated browser-in-the-browser (BitB) attack to harvest both credentials and multi-factor authentication codes in real time.
How the Browser-in-the-Browser Attack Works
Victims land on a site impersonating a popular AI platform and are prompted to "Connect" their Google account to unlock some feature. Clicking it opens what looks like a legitimate Google OAuth pop-up — complete with a realistic address bar showing accounts.google.com. In reality, that "pop-up" is an iframe rendered inside the page itself, with the phishing site locally rebuilding the Google login interface to collect credentials directly.
Once a victim enters their password, a live human operator takes over the session and can:
- Request the password again if the first attempt looks wrong
- Prompt the victim for an SMS or authenticator app code
- Display a fake Okta push notification or Google approval prompt
- Reject submitted codes, stall victims on a waiting screen, or terminate the session at will
This human-in-the-loop design lets operators relay stolen MFA codes to the real login page within the code's validity window — defeating time-based one-time passwords and app-based push approvals that would otherwise stop simple credential phishing.
Who's Being Targeted
| Target | Why |
|---|---|
| Agency staff | Manage ad accounts across many clients |
| Media buyers | Control active ad spend and budgets |
| Ad administrators | Hold elevated permissions on platform accounts |
Compromised accounts give attackers the ability to launch fraudulent ad campaigns against the victim's budget or resell the stolen access to other cybercriminals — both lucrative outcomes given the spending authority these roles typically carry.
Infrastructure and Scope
Researchers traced the campaign's infrastructure — built on Next.js and Socket.IO — back to March 2026 through exposed GitHub repositories, and have identified dozens of URLs themed around ads, refunds, and recruitment lures.
The Attack's Weakness
Browser-in-the-browser attacks have a structural limitation that defenders can use for detection: the fake pop-up is an iframe confined to the browser window. Unlike a genuine OAuth pop-up, it cannot be dragged outside the browser's boundaries or resized independently — if a "Google sign-in window" won't move past the edge of your browser tab, that's a strong signal it's fake.
Recommended Actions
- Train ad-ops and agency staff specifically on the browser-in-the-browser tell: try dragging any login pop-up outside the browser window before entering credentials
- Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys) on advertising platform accounts — these cannot be relayed by a human operator the way SMS or TOTP codes can
- Restrict and monitor ad account permissions, limiting spend authority to the minimum needed per role
- Block known campaign infrastructure at the network/DNS layer where threat intelligence feeds have indexed it
- Report suspicious "Connect your account" prompts on any site claiming to be ChatGPT, Gemini, Claude, or Perplexity — none of these platforms require linking a Google ad account to use their core chat features