Fake AI Ad Portals Steal Logins and MFA Codes

The Hacker News · High sophistication
Last updated October 7, 2026

Researchers uncovered a human-run phishing platform that pretends to be ad-management products for popular AI brands (ChatGPT, Gemini, Claude, and others). Victims are pushed to click a “Connect” flow that opens a convincing fake login window (showing trusted domains like accounts.google.com) to steal passwords and MFA codes in real time. The stolen access is then used to take over advertising/manager accounts, add attacker admins, and monetize the accounts by running ads or selling them.

How the attack worked

A human-operated phishing platform built a set of convincing lookalike products impersonating AI advertising tools tied to brands like ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus. Each fake product had its own branding, pitch, and sign-in flow, but all shared a single call to action: a prominent Connect button. Clicking it triggered a browser-in-the-browser (BitB) window, a fake login popup drawn inside the page that displayed trusted-looking addresses such as accounts.google.com or an Okta tenant, even though the real browser never left the phishing domain. One identified site, museads.ai, pitched itself as an AI ads manager offering campaign optimization and spend audits to lure victims into connecting their business ad accounts.

Why it succeeded

The realism of the fake login window was central to the scheme's success. Because the address bar shown to the victim matched a familiar, trusted domain, many users would have little reason to suspect anything was wrong. Victims are assessed to have been driven to these landing pages through fake invitation emails impersonating trusted AI brands, adding a layer of legitimacy before the victim ever reached the fake portal. Behind the scenes, the platform recorded every password attempt, fingerprinted the device, and let a human operator choose which MFA challenge to present next, allowing real-time interception of one-time codes rather than relying on a static, easily-detected phishing kit.

Who was targeted and why

The likely targets were advertising agencies, specifically media buyers, marketing staff, and manager-account administrators with access to ad platforms. The goal was not simple credential theft for its own sake but account takeover: gaining control of accounts with established, clean spend histories so they could be monetized directly through ad spend or resold.

What to watch for

  • Unsolicited invitations or beta offers urging you to connect business ad accounts to a new tool
  • A sign-in box that appears to float inside a webpage rather than opening a genuine new browser tab or window
  • Requests to authenticate across multiple identity providers (Google, Meta, TikTok, Okta) from an unfamiliar product
  • Unexpected MFA prompts that do not match the action you intended to take

Building resistance

Organizations should treat unsolicited connect-your-account invitations as high risk and verify sender and destination domains before clicking. Teams should be trained to recognize that legitimate sign-ins open in the browser's real address bar, not inside a page element. Since MFA codes can be captured and relayed in real time, phishing-resistant authentication methods are recommended. Finally, monitoring advertising account admin changes helps catch takeovers early, since attackers typically add their own administrators and downgrade legitimate owners after gaining access.

Key findings

  • A “human-operated phishing platform” impersonated AI chatbot advertising products (ChatGPT, Gemini, Claude, Perplexity, Meta Muse, Manus) to steal credentials and MFA codes.
  • The sites used a browser-in-the-browser (BitB) fake login window that displayed trusted-looking origins like accounts.google.com or an Okta tenant while keeping the real page on a phishing domain.
  • The platform recorded password attempts, fingerprinted devices, and let an operator choose which MFA challenge the victim saw next.
  • At least one identified site was museads.ai, which presented an AI ads manager pitch and used a “Connect” button to trigger the credential/MFA capture flow.
  • Victims were assessed to be driven to the landing pages via fake invitation emails impersonating trusted brands.
  • The likely targets are advertising agencies (agency staff, media buyers, manager-account administrators) with the goal of monetizing/selling ad accounts and abusing clean spend histories.

Who’s being targeted

  • Commonly targeted roles: Marketing, Media buying, Advertising operations, Agency account administrators, IT/Identity & Access Management.
  • Affected industries: Advertising agencies, Digital marketing, Media buying.
  • Attack channels: website, email.
  • Impersonated: Meta Muse ads product (lookalike AI ads portal), ChatGPT/Gemini/Claude (trusted AI brand invitations).

Red flags to watch for

  • A login window appears inside the browser (not a real separate login page), while the underlying site is a different domain.
  • The page shows a trusted-looking domain in a fake address bar (e.g., accounts.google.com) even though you are still on the phishing site.
  • Unexpected request to connect multiple identity providers (Google/Meta/TikTok/Okta) from a brand-new tool/site.
  • Unsolicited “beta invite” urging you to connect business ad accounts quickly.
  • Link goes to a lookalike or unfamiliar domain for the purported brand/product.
  • Login prompt appears in an embedded/fake window rather than a normal, full-page sign-in.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a browser-in-the-browser (BitB) attack?

It is a fake login window drawn inside a webpage that mimics a real sign-in popup, showing a trusted-looking address like accounts.google.com while the actual site stays on the attacker's phishing domain.

Why are advertising agencies being targeted?

The attackers aim to take over ad manager accounts with clean spend histories, then add their own administrators and monetize the accounts by running ads or selling access.

Does MFA protect against this attack?

Not fully. The platform recorded password attempts and let an operator choose which MFA challenge the victim saw, capturing codes in real time, so phishing-resistant authentication is recommended.

How are victims lured to these fake AI ad portals?

Victims are assessed to be driven to the landing pages through fake invitation emails impersonating trusted AI brands like ChatGPT, Gemini, and Claude.

Read the video transcript

You get an email: “Invitation to connect your AI Ads portal (beta)” for ChatGPT or Gemini. Looks legit, right? You click through to a site like museads.ai, promising AI campaign optimization. Front and center is a big “Connect” button. Click it, and a fake login window pops up inside the page showing accounts.google.com or your Okta tenant. This is a browser-in-the-browser, or BitB, attack. Every password try is logged, and the operator even chooses which MFA challenge you see, so they can steal codes in real time and add themselves as admins to your ad accounts. Aha test: if a Google, Meta, TikTok, or Okta login box appears inside another page, stop. Don’t log in there, open a fresh tab and go to the provider’s site directly.

Similar attacks

NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
Fake ChatGPT Invoice Email Steals Logins

Fake ChatGPT Invoice Email Steals Logins

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

September 18, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026