# Human-Operated Phishing Steals AI Ad Account Credentials

> A sophisticated human-operated phishing platform impersonates AI chatbot ad portals to steal credentials and MFA codes from media buyers and account administrators.

- Published: 2026-10-06T20:40:06.000Z
- Severity: high
- Category: Threat Intel
- Tags: Phishing, Credential Theft, MFA Bypass, AI, Social Engineering
- Author: Runtime Rebel Intel
- Primary source: https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
- Canonical: https://runtimerebel.com/blog/human-operated-phishing-steals-ai-ad-account-credentials

## Key points

- Immediate impact: Phishing platform actively steals credentials and MFA codes from users of AI ad services.
- Affected systems: Users connecting Google, Meta, TikTok, and Okta accounts to various AI ad platforms are targeted.
- Remediation: Implement phishing-resistant MFA and rigorously vet all AI integrations before connecting accounts.

## Overview: [AI](/glossary#ai) Ad Portal [Phishing](/glossary#phishing) Campaign

Cybersecurity researchers have uncovered details of a sophisticated "human-operated phishing platform" designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. This platform's primary objective is to capture user credentials and multi-factor authentication ([MFA](/glossary#mfa)) codes by deploying a highly deceptive technique known as the browser-in-the-browser (BitB) trick.

The campaign targets agency staff, media buyers, and manager-account administrators, aiming to compromise valuable ad accounts. Successful compromise can lead to significant financial losses, as attackers may use these accounts to run their own ad campaigns, drain budgets, or sell accounts with good reputations on underground markets. Recovery for victims can be a prolonged process, often taking weeks or months, while the compromised account continues to serve malicious or unauthorized ads, potentially impacting an agency's clients, according to [The Hacker News](https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html).

## Technical Analysis of the Phishing Platform

The identified phishing platform operates by creating fake advertising products that promise features like campaign optimization, spend audits, and business-account connections. Each impersonated AI brand, such as ChatGPT or Gemini, is given a tailored pitch to enhance legitimacy. For example, 'museads.ai' emerged shortly after Meta launched its Muse [AI agent](/glossary#ai-agent), positioning itself as "Your AI ads manager for paid media workflows."

### Browser-in-the-Browser (BitB) [Attack Vector](/glossary#attack-vector)

The core of this threat lies in its use of the browser-in-the-browser (BitB) trick. When a user clicks a 'Connect' button on the spoofed web page – typically found within a prominent 'Prompt Box' – a fake browser window is drawn inside the real browser. This fake window displays a bogus sign-in form for legitimate services like Google, Meta, TikTok, or Okta, complete with a seemingly authentic address bar pointing to trusted origins such as accounts.google[.]com or an Okta tenant. Crucially, the real browser's address bar remains on the phishing domain, a detail often overlooked by unsuspecting users.

Behind this deceptive interface, the **human-operated phishing platform analysis** reveals that the system continuously logs every password attempt. It also fingerprints the victim's device, transmitting this data to the attacker. An operator then actively controls the MFA challenge presented to the victim, facilitating real-time credential and MFA code capture. This allows the attacker to immediately attempt sign-in with the stolen credentials, increasing the success rate of account takeover.

### Broader Campaign Infrastructure

Island researchers note that these AI ads pages are part of a larger phishing operation. The broader platform supports a three-pronged approach that also includes Google Ads-themed refund claims and payment confirmations, as well as recruitment-related sites for well-known brands like Tesla, Louis Vuitton, Nike, and Adecco. All these identified websites share a common technology stack, primarily Next.js and Socket.IO, and communicate with the same backend endpoints. Furthermore, earlier versions of the platform's source code were exposed through misconfigured public GitHub repositories, indicating a degree of operational sloppiness by the threat actors.

The widespread commodity crime of ad account theft, previously facilitated by [malware](/glossary#malware) families like VietCredCare, DuckTail, NodeStealer, and PXA Stealer, demonstrates the lucrative nature of compromising advertising ecosystems. This phishing campaign capitalizes on that established illicit market, aiming to acquire accounts with clean spend histories for maximum profit.

## Actionable Recommendations and Mitigation Strategies

Organizations and individuals, particularly those involved in media buying and ad account management, must adopt proactive measures to protect against such sophisticated phishing attacks.

*   **Enable Phishing-Resistant Multi-Factor Authentication (MFA):** Implement hardware-based security keys (e.g., FIDO2/WebAuthn) or certificate-based authentication wherever possible. These methods are highly resistant to phishing and BitB attacks, unlike SMS or app-based MFA codes which can be intercepted in real-time by human-operated platforms.
*   **Scrutinize AI Integrations:** Before connecting any advertising accounts to new AI integration platforms, rigorously vet their legitimacy. Verify the provider through official channels, read reviews, and understand the permissions being requested. This is key for **preventing AI ad account [credential theft](/glossary#credential-theft)**.
*   **Educate on Browser-in-the-Browser Attacks:** Train staff to recognize the subtle indicators of BitB attacks. Emphasize the importance of always checking the *actual* browser's URL bar, not just the one displayed within a pop-up window. Genuine login prompts will always reflect the trusted domain in the main browser window's address bar. This awareness is crucial for **browser-in-the-browser attack mitigation**.
*   **Review Advertising Control Changes:** Regularly audit permissions and administrative access for all advertising accounts. Be alert for any unauthorized changes, such as the addition of new administrators or the downgrading of legitimate owners.
*   **Beware of Unsolicited Communications:** Exercise extreme caution with invitation emails or advertisements promoting new AI ad management tools, especially if they are unsolicited or come from unknown senders, regardless of how legitimate they appear. Always navigate directly to official vendor websites.

**Related:** [LastPass & Bitwarden Phishing: Analyzing Fake Security Alerts](/blog/lastpass-bitwarden-phishing-analyzing-fake-security-alerts), [AI Transforms Social Engineering: Phishing & Deepfake Threats](/blog/ai-transforms-social-engineering-phishing-deepfake-threats)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/human-operated-phishing-steals-ai-ad-account-credentials
