MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne Pages — Threadlinqs Intelligence
As of 2026-07-19, MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne Pages is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1522 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
PreCrime Labs (BforeAI) uncovered an organized phishing operation impersonating MetaChat, an AI aggregation platform offering 30+ AI models (ChatGPT, Gemini, Claude, Midjourney, Grok, DeepSeek).
PreCrime Labs, the research division of BforeAI, identified a semi-automated phishing cluster impersonating MetaChat, a legitimate AI aggregation service that provides unified access to more than 30 AI models under one account, including ChatGPT, Gemini, Claude, Nano Banana, Midjourney, Grok, and DeepSeek. Approximately 18 lookalike domains were discovered, all hosted on Tencent's EdgeOne Pages free static-site hosting platform and following a predictable three-part naming convention: metachat-backend-[unique-id].edgeone.app, where [unique-id] is a randomly generated 10-character alphanumeric string. This naming pattern indicates semi-automated or scripted domain registration/provisioning rather than manual, one-off phishing kit deployment, enabling the operators to rapidly rotate infrastructure and outpace naive blocklist-based defenses.
Each phishing site clones the MetaChat login/registration flow and wires a set of purpose-built backend endpoints to harvest distinct categories of victim data: /user-register and /user-login capture account credentials (email, username, password, phone number); /user-api-key and /user-api-info capture AI API keys, access tokens, and account metadata for the platforms MetaChat aggregates; /user-recharge, /orders, and /chat/payment capture payment card and WeChat Pay transaction data tied to fraudulent 'recharge' (top-up) flows; /approval-token-withdraw captures internal session/approval tokens tied to withdrawal authorization; and /user-referees together with a SubAgentRefereeRechargePackage endpoint map the victim's referral network, indicating the operators are also running a two-tier MLM-style referral/commission fraud scheme layered on top of the credential theft.
Monetization is multi-pronged: stolen AI API keys and access tokens (for Claude, ChatGPT/Cursor, and other premium AI subscriptions) are resold on underground/cybercrime forums for unauthorized service consumption; WeChat Pay 'recharge' flows are abused to directly defraud victims of funds; and the referral/MLM structure incentivizes victims (and complicit distributors) to recruit further victims, amplifying reach. Because EdgeOne Pages is a free, low-friction hosting service backed by Tencent's legitimate CDN/edge infrastructure, phishing pages inherit a degree of implicit trust and evade reputation-based blocking that would flag cheaper or newly-registered standalone domains.
A secondary distribution vector uses malvertising via sponsored/paid search placements to route victims to lookalike pages impersonating other AI brands — for example, claude-app-new.gitlab.io impersonating Claude Code — placed above official links to exploit user purchase/download intent. This is consistent with a broader wave of AI-brand malvertising/impersonation activity observed across GitLab Pages and Google Ads in 2026 (a related, larger campaign used 92+ unique malicious GitLab Pages hostnames impersonating Claude Code, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains, paired with ClickFix-style social engineering to get victims to paste and execute malicious terminal/PowerShell commands). While the GitLab/ClickFix cluster is a distinct, malware-delivery-focused campaign, PreCrime Labs flags it as part of the same overall trend of attackers weaponizing the trust and hype around AI tools to target both credentials and endpoints.
Detection guidance from the source emphasizes flagging any newly registered subdomain on free hosting providers (EdgeOne Pages, GitLab Pages, and similar) that combines a 'backend'-style identifier with AI-specific keywords ('metachat', 'ai', 'api', 'chat', 'gpt', 'key') or financial-fraud keywords ('recharge', 'wallet', 'login'), particularly when the domain is registered/provisioned 30-60 days before becoming active in phishing distribution — a pattern PreCrime Labs' predictive models used to identify the cluster before full-scale abuse.
Weaknesses (CWE)
CWE-1021, CWE-451, CWE-290
Target sectors: technology, individualconsumers, softwaredevelopment, finance
Target regions: Global, Asia-Pacific, china
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1584, T1587, T1585, T1566, T1566, T1189, T1204, T1204