Researchers found a real phishing operation that pretends to offer AI marketing tools (e.g., “Muse Ads”) and prompts users to click “Connect” to log in. The login pop-up looks like Google or Okta, but it’s a fake browser window embedded inside the webpage, designed to steal passwords and MFA codes, sometimes with a live human operator controlling the prompts.
How the attack worked
This campaign impersonated AI advertising and marketing tools tied to well-known brand names, including tools resembling ChatGPT, Gemini, Claude, Perplexity, Manus, and Meta's Muse. Every fake product was built around a single consistent lure: a button labeled Connect that promised ad planning or audit features in exchange for linking a Google or Okta account. Clicking Connect launched a fake login experience rather than a real integration, designed specifically to capture credentials and MFA information from marketing, advertising operations, media buyer, and agency account manager roles.
Why the login trap was convincing
The core deception relied on Browser-in-the-Browser, a technique that renders a convincing fake browser window directly inside the real webpage. This fake window could display trusted-looking addresses such as accounts.google.com or an Okta tenant, even though the actual browser address bar remained on the attacker's domain the entire time. Because the imitation closely mirrored real Google or Okta sign-in flows, victims had little visual reason to suspect anything was wrong.
Interactive, operator-driven MFA theft
What made this platform especially dangerous was its support for live, interactive MFA theft. It could retain multiple password attempts, request SMS or authenticator codes, trigger Google approval prompts, display QR codes, and send Okta push requests. In some cases a human operator actively controlled which MFA challenge the victim saw, and could reject submitted codes and ask victims to try again, maximizing the chance of capturing a usable code or approved push before it expired.
Why advertising and agency roles were targeted
Targets included ad agencies, media buyers, and admin roles because a single compromised ad manager account can expose multiple client environments along with spending authority. This makes identity administrators managing Okta or Google Workspace, agency account managers, and executive assistants who approve ad spend especially high-value targets for this type of credential theft.
What to watch for and how to build resistance
- Treat any unexpected request from an AI service to connect a Google, Meta, TikTok, or Okta account as an account-access request, not a harmless integration.
- Check the browser's actual address bar rather than any address displayed inside the page content itself.
- Test suspicious login windows by trying to move or resize them, since a fake browser window embedded in a webpage cannot behave like a genuine browser window.
- Treat repeated MFA prompts or requests to retry a code as a warning sign rather than a technical glitch.
- Favor phishing-resistant passkeys and hardware-backed authentication, which bind authentication to the legitimate site rather than relying on a password or code a user can be tricked into revealing.
- After suspected exposure, review advertising accounts for unfamiliar administrators, partners, recovery changes, and campaigns, and reset access immediately if credentials or MFA codes were entered.
Key findings
- Attackers posed as AI advertising/marketing tools for well-known brands (ChatGPT, Gemini, Claude, Perplexity, Manus, and Meta’s Muse).
- The lure is a consistent “Connect” action that launches a fake login experience to steal credentials and MFA.
- The campaign uses Browser-in-the-Browser (BitB) to display a convincing fake login window inside the real browser.
- The platform supports interactive MFA theft (SMS codes, authenticator codes, Google prompts, QR codes, Okta push) and can force victims to retry codes.
- Targets include ad agencies, media buyers, and admin roles because one stolen ad manager account can expose multiple client environments and spending authority.
Who’s being targeted
- Commonly targeted roles: Marketing, Advertising Operations, Media Buyers, Agency Account Managers, IT/Identity & Access Management (Okta/Google Workspace admins), Executive assistants/approvers for ad spend.
- Affected industries: Advertising and marketing agencies, Media buying, Digital marketing teams, Organizations using Google/Okta identities.
- Attack channels: website.
- Impersonated: Meta Muse / AI marketing service provider, Google sign-in / Okta tenant (shown inside a fake browser window).
Red flags to watch for
- Login window appears inside a webpage and may not behave like a real browser window when you try to move/resize it
- Brand-new AI service appears immediately after a product launch and unexpectedly requests access to Google/Okta/TikTok/Meta accounts
- Repeated MFA prompts or requests to ‘try again’ after a correct code
- The page shows a ‘trusted address’ inside the content, but the real address bar is different
- Unexpected push requests/QR codes tied to an unfamiliar ‘AI ads’ integration
- Operator-like behavior (codes rejected, asked to re-enter multiple times)
Frequently asked questions
What is Browser-in-the-Browser (BitB) phishing?
It is a technique that places a convincing fake browser window inside the real browser's webpage content, making a phishing login page look like a genuine Google or Okta sign-in popup while the actual browser stays on the attacker's domain.
How can I tell a fake login window from a real one?
Check the browser's actual address bar rather than any address shown inside the page, and try to move or resize the login window, since a fake window rendered inside a webpage cannot behave like a genuine browser window.
Why are advertising and marketing teams targeted?
One stolen ad manager account can expose multiple client environments and spending authority, making roles like media buyers, agency account managers, and ad operations high-value targets.
Can MFA codes still be stolen if I use SMS or authenticator codes?
Yes, a one-time code can still be stolen if entered into an attacker-controlled page while a human operator is waiting to use it, and operators can reject codes and ask victims to retry to capture a usable one.
Read the video transcript
You see a shiny new “Muse Ads” AI tool: ChatGPT, Meta, Google logos everywhere, and one big button: Connect. You click Connect and a Google or Okta login pops up. Looks legit, right? This is Browser‑in‑the‑Browser, a fake window inside the page built to grab your password and MFA codes. Behind the scenes, a live operator can keep rejecting your SMS, authenticator, or Okta push, "try again", until they get a usable code and walk straight into every ad account you manage. Here’s your move: if any AI ads tool asks you to Connect Google, Okta, Meta, or TikTok, stop and read the real browser address bar, if the domain’s off, close it and report it.