Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Hackers Impersonate ChatGPT, Gemini and Claude to Steal Advertising Accounts

Hackers Impersonate ChatGPT, Gemini and Claude to Steal Advertising Accounts

By:
Last updated:October 8, 2026
Human Written
  • A human-run phishing platform impersonates ChatGPT, Gemini, Claude, Perplexity, Manus and Meta’s Muse to steal account credentials and MFA codes.

  • The campaign uses fake browser windows that can display trusted Google or Okta addresses while the victim remains on the phishing site.

  • The attackers target advertising professionals because stolen ad accounts can expose client accounts, drain budgets or fetch money on criminal markets.

Hackers Target Advertising Accounts With Fake ChatGPT and Gemini Tools

Cybersecurity researchers just found a phishing scam that pretends to offer AI advertising tools but actually steals business account logins and MFA codes. The attackers pose as top AI brands like ChatGPT from OpenAI, Google Gemini, Anthropic’s Claude, Perplexity, Manus, and Meta’s Muse.

The fake services claim to offer useful tools for advertisers. There are campaign planning tools, budget audit, account integration, and many more features offered by them.

Nevertheless, the actual aim of these fake service providers is to steal accounts. Two Island researchers, Oleg Zaytsev and Ofek Ronen, discovered a human-run phishing platform behind this campaign. The attackers can watch victims in real time and change the login process as needed.

Fake Sites Masqueraded as Advertising Solutions

The attackers did not rely on basic login pages. Instead, they created full websites that look like advertising products. Each site uses a different brand and sales pitch. For example, the fake ChatGPT service promises a Monday Google Ads brief. The Gemini version offers manager-account and linked-client support.

Meanwhile, the Claude site presents an advertising portal. Perplexity offers campaign planning and spending audits. Manus promotes a private Meta integration. The newest lure was Muse Ads. Meta launched its Muse personal AI agent on September 8, 2026. Eight days later, Island found museads.ai promoting a fake advertising product.

The site called itself “Your AI ads manager for paid media workflows.” It promises to help advertisers connect with buyers and manage their ad accounts and sponsorships. It is significant since the hackers were able to modify their phishing bait in accordance with a brand-new popular AI brand.

Site Connect Button Triggers the Trap

The attack centers on a simple Connect button. When a victim clicks it, the site does not send them to the real Google or Okta login page. Instead, it draws a fake browser window inside the existing webpage.

This technique is called Browser-in-the-Browser, or BitB. The fake window can look convincing. It can show a lock icon and an address bar displaying a trusted address such as accounts.google.com.

However, the real browser still sits on the attacker’s domain. The platform can also copy browser details from different devices. Island found versions that imitate Chrome, Safari and mobile browser interfaces. As a result, a victim may believe they are looking at a normal Google or Okta login screen, even though they’re not.

Human Operators Control the Login Flow

The campaign goes beyond collecting a username and password. Island found that human operators can control the victim’s authentication process while it happens. When someone clicks Connect, the platform creates a victim record. It then collects device information such as IP address, location, screen size, and WebGL data.

The system allows multiple password attempts, so the operator can ask the victim to enter their password up to three times. If one password doesn’t work, the operator can reject it and prompt the victim to try again.

On top of that, the platform offers lots of ways to handle multi-factor authentication. For Google accounts, operators can send approval prompts, ask for QR codes, or use number matching. With Okta, they can request SMS codes, authenticator app codes, push approvals, and number matching too.

The system can even reject a submitted MFA code. The attacker is given another opportunity to get a legitimate code if the previous try does not work.

Commands are passed to the phishing website through Socket.IO events so that the keeper can decide what the victim will see. Island also discovered the system can keep victims waiting on a screen or end their session, depending on what the operator wants to do next.

One Platform Powers Several Scams

The AI advertising pages are only one part of the operation. Island found the same technology behind fake refund and payment pages. The platform can also be used to create fraudulent recruitment websites featuring such brands as Tesla, Louis Vuitton, Nike, and Adecco.

The attacks were made with the same technological background. Island found a common stack created using Next.js and Socket.IO.

Researchers also found shared backend infrastructure connecting different scam pages. One backend appeared in 73 archived scans across 25 domains between May 27 and June 20. The domains featured fake AI advertising offers, money-back pages and a fraudulent Louis Vuitton career page.

They also accidentally revealed their old version of the code from public repositories on GitHub. That exposure helped Island trace how the operation evolved. This attack demonstrated that the hackers were able to use the same platform for different victims. They just had to change the brand, offer, and login procedure.

Advertising Accounts Offer a Valuable Prize

The campaign seems to target the staff of the agency, media buyers, and manager-account administrators. This is reasonable as the advertising accounts have the ability to manage money and the campaigns of clients.

However, there is the possibility that the compromised manager account may have a link to many client accounts. This means that with just one stolen identity, an attacker would be able to gain access to multiple advertising operations. This includes conducting their campaigns and selling off the established accounts.

A separate Mimecast study identified a growing market for stolen advertising accounts. Its research describes attackers using compromised accounts to spend advertising budgets or sell accounts with established histories.

Even after a company deletes a payment card, the trouble doesn’t just end there. Attackers might stick around; they can add their own admins or change account permissions to retain control. This means victims often deal with a much tougher and longer recovery process. And for agencies, their clients can get caught up in the mess too.

MFA does not Always Stop Phishing

The campaign also highlights a weakness in traditional MFA. MFA can stop many account attacks. However, it hardly helps if someone hands over their code on a fake login page and an attacker uses it right away. That’s exactly why you need phishing-resistant authentication.

Tools like passkeys and hardware security keys make a real difference since they only work with the real website. Attackers didn’t start from scratch. They took an old phishing platform and slapped on new branding and a slick sales pitch. Attackers have used ChatGPT in other campaigns as well, including one that abused Custom GPTs to spread ClickFix malware and a remote access trojan.

Companies should also verify new AI products before connecting business accounts. A new advertising tool may look legitimate because it uses familiar branding. However, users should confirm the product through the vendor’s real website before entering credentials.

Island’s findings show how quickly phishing campaigns can follow technology trends. Muse Ads appeared only eight days after Meta launched Muse. Attackers didn’t start from scratch. They took an old phishing platform and slapped on new branding and a slick sales pitch. That approach lets criminals react quickly when a new AI product gains attention.

Island said it observed hundreds of victim submissions during its research. The company did not describe those submissions as hundreds of confirmed account compromises. Activity also remained ongoing when researchers published their findings.

This fact is noteworthy for defenders. This campaign proves attackers can dress up a phishing site to look like a genuine business service, not just another sketchy login screen.

So, security teams need to stay sharp. Watch out for fake AI tools, weird requests to connect accounts, and out-of-the-blue advertising admins showing up. These are the signs something’s off.

Most importantly, users should check the real browser address before signing in. A webpage can draw a fake address bar. It cannot change the actual address shown by the browser. That simple check can expose the trick before a convincing “Connect” button turns a routine AI workflow into an account takeover.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.