Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes: A Threat to AI-Powered Security




A recent phishing campaign has been discovered that impersonates advertising products for AI chatbots, capturing credentials and MFA codes via spoofed login windows. The phishing platform, which is part of a broader phishing campaign, has been found to target agency staff, media buyers, and manager-account administrators, with the end goal of monetizing ads accounts. To mitigate the threat, organizations are recommended to enable phishing-resistant authentication, review advertising control changes, and scrutinize AI integrations before connecting accounts.

The phishing platform uses a technique called the "browser-in-the-browser" (BitB) trick to spoof the login windows and capture the victim's account credentials. The attackers can use the captured credentials to sign in to the account in real-time. The phishing platform is part of a broader phishing campaign that also includes Google Ads-themed refund claims and payment confirmation, as well as recruitment-related sites for Tesla, Louis Vuitton, Nike, and Adecco.

The threat actors behind the operation have exposed source code for earlier versions of the platform through misconfigured public GitHub repositories. This has made it easier for security researchers to understand the scope of the phishing campaign and identify the vulnerabilities that can be exploited by attackers. The AI ads-focused campaign is designed to target agency staff, media buyers, and manager-account administrators, likely with the end goal of monetizing the ads accounts to run their own ad campaigns or sell them for profit, especially when they have a clean spend history.

To stay ahead of the phishing threats, it is essential to be aware of the tactics used by attackers and to take proactive measures to protect your organization's security. This can include enabling phishing-resistant authentication, reviewing advertising control changes, and scrutinizing AI integrations before connecting accounts. By taking these steps, you can help prevent the phishing campaign from succeeding and protect your organization's sensitive information.

  • AI chatbots and assistants are vulnerable to phishing platforms that impersonate advertising products.
  • The phishing platform targets agency staff, media buyers, and manager-account administrators to steal credentials and MFA codes.
  • The platform uses the "browser-in-the-browser" (BitB) trick to spoof login windows and capture account credentials.
  • The attack is part of a broader phishing campaign targeting ad accounts for profit.
  • Organizations should enable phishing-resistant authentication, review advertising control changes, and scrutinize AI integrations to mitigate the threat.



  • The world of artificial intelligence (AI) has made tremendous progress in recent years, with AI-powered chatbots and assistants becoming an integral part of our daily lives. Among the most popular AI chatbots are Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. However, the recent discovery of a "human-operated phishing platform" that impersonates advertising products for these AI chatbots has raised serious concerns about the security of these platforms. The phishing platform, which was designed to capture credentials and multi-factor authentication (MFA) codes via spoofed login windows, has been found to target agency staff, media buyers, and manager-account administrators.

    The phishing platform, which is part of a broader phishing campaign that also includes Google Ads-themed refund claims and payment confirmation, as well as recruitment-related sites for Tesla, Louis Vuitton, Nike, and Adecco, uses a technique called the "browser-in-the-browser" (BitB) trick to spoof the login windows. This technique allows the phishing platform to capture the victim's account credentials, fingerprint the device, and transmit the information to the attacker at the endpoint "/api/send/ip" over Socket.IO. The attacker can then use the captured credentials to sign in to the account in real-time.

    The phishing platform, which was built around the same action: "Connect," is designed to pose as a believable product, with its own brand, pitch, and sign-in flow. The platform uses a three-pronged operation, which includes Google Ads-themed refund claims and payment confirmation, as well as recruitment-related sites for Tesla, Louis Vuitton, Nike, and Adecco. All the identified websites have been found to share the same technology stack comprising Next.js and Socket.IO, and communicate with the same endpoints.

    The threat actors behind the operation have exposed source code for earlier versions of the platform through misconfigured public GitHub repositories. This has made it easier for security researchers to understand the scope of the phishing campaign and identify the vulnerabilities that can be exploited by attackers.

    The AI ads-focused campaign is designed to target agency staff, media buyers, and manager-account administrators, likely with the end goal of monetizing the ads accounts to run their own ad campaigns or sell them for profit, especially when they have a clean spend history. According to a report published by Mimecast in July 2026, malware families like VietCredCare, DuckTail, NodeStealer, and PXA Stealer have engendered ad account theft at scale, leading to a "widespread commodity crime in the advertising ecosystem" where bad actors drain business budgets and sell accounts with good reputation in underground markets.

    To mitigate the threat, organizations are recommended to enable phishing-resistant authentication, review advertising control changes, and scrutinize AI integrations before connecting accounts. The disclosure comes as Island revealed that threat actors are abusing Google-sponsored results to route unsuspecting users to custom GPTs or shared-AI chat content, which then redirect them to a fake Cloudflare verification page serving ClickFix-style lures to deliver NetSupport RAT.

    The campaign did not require a vulnerability in ChatGPT or Google, but rather abused trusted platforms, attacker-authored content, paid search, and social engineering to move people toward malware delivery. Across a three-month observation period ending in August 2026, the broader delivery cluster included about 850 paid-ad landings, 26 lookalike ChatGPT destinations, and 71 Google Ads campaign IDs.

    The recent discovery of the phishing platform that impersonates advertising products for AI chatbots has raised serious concerns about the security of these platforms. The phishing platform, which was designed to capture credentials and MFA codes via spoofed login windows, has been found to target agency staff, media buyers, and manager-account administrators. The phishing platform uses a technique called the "browser-in-the-browser" (BitB) trick to spoof the login windows and capture the victim's account credentials. The attackers can use the captured credentials to sign in to the account in real-time.

    The phishing platform is part of a broader phishing campaign that also includes Google Ads-themed refund claims and payment confirmation, as well as recruitment-related sites for Tesla, Louis Vuitton, Nike, and Adecco. All the identified websites have been found to share the same technology stack comprising Next.js and Socket.IO, and communicate with the same endpoints. The threat actors behind the operation have exposed source code for earlier versions of the platform through misconfigured public GitHub repositories.

    The AI ads-focused campaign is designed to target agency staff, media buyers, and manager-account administrators, likely with the end goal of monetizing the ads accounts to run their own ad campaigns or sell them for profit, especially when they have a clean spend history. According to a report published by Mimecast in July 2026, malware families like VietCredCare, DuckTail, NodeStealer, and PXA Stealer have engendered ad account theft at scale, leading to a "widespread commodity crime in the advertising ecosystem" where bad actors drain business budgets and sell accounts with good reputation in underground markets.

    To mitigate the threat, organizations are recommended to enable phishing-resistant authentication, review advertising control changes, and scrutinize AI integrations before connecting accounts. The disclosure comes as Island revealed that threat actors are abusing Google-sponsored results to route unsuspecting users to custom GPTs or shared-AI chat content, which then redirect them to a fake Cloudflare verification page serving ClickFix-style lures to deliver NetSupport RAT.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Fake-ChatGPT-Gemini-and-Claude-Ad-Portals-Capture-Credentials-and-MFA-Codes-A-Threat-to-AI-Powered-Security-ehn.shtml

  • https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html


  • Published: Tue Oct 6 17:24:32 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us