Threat reportPhishingTL-2026-2977
Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use Browser-in-the-Browser Phishing to Steal Ad Account Credentials and MFA Codes
Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use (TL-2026-2977), also tracked as The Fake AI Ads Campaign, is a high-severity phishing campaign, first published 2026-10-06 and last reviewed 2026-10-10. It has no confirmed attribution, affects Google Google Ads / Google accounts (manager accounts), maps to 16 MITRE ATT&CK techniques (T1036, T1056.003, T1071.001), and is covered by 9 detection rules and 54 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 54Indicators of compromise
Key facts for TL-2026-2977
- Threat ID
- TL-2026-2977
- Also known as
- The Fake AI Ads Campaign, Behind the Connect Button
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- advertising, marketing agencies, media buying, ecommerce, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 54
- Updates
- 2026-10-10 · 2 updates · revalidated 2× · latest source
Malware and tooling in Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use
Malware and tooling: Telegram
How Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use works
A human-operated phishing platform impersonates AI advertising products (ChatGPT, Gemini, Claude, Perplexity, Manus and, newest, Meta Muse Ads) and presents a fake OAuth popup via Browser-in-the-Browser (BitB) to harvest Google, Meta, TikTok and Okta credentials and MFA codes. Operators steer each victim through MFA challenges in real time over Socket.IO and a Telegram control channel, targeting agency staff, media buyers and manager-account administrators.
Island researchers documented a phishing platform presented as a portfolio of AI advertising products. Every lure is built around a single 'Connect' button. Clicking it opens a browser window drawn inside the page (Browser-in-the-Browser), with a fake address bar showing accounts.google.com or an Okta tenant while the real browser stays on the phishing domain. The fake window imitates Safari's URL pill, Chrome custom tabs and a dark mode, with translucent iOS toolbar styling so it does not look painted on.
The stack is a Next.js frontend (hosted on Vercel) talking over Socket.IO to a backend on Railway or Render. The backend keeps every password attempt (password_one, password_two, password_three), fingerprints the device (IP, geolocation through ipify/ipapi.co, screen size, WebGL capabilities) and lets a human operator pick the next MFA challenge the victim sees. Operator directives follow an authentication state machine (/password, /2fa, /authApp, /googlePrompt, /googleQrVerify, /verifyTap, /oktaApprove, /oktaAuthApp, /wrong2fa, /done, /ban), carried on the operator-command and telegram-command Socket.IO events. The platform handles SMS and authenticator codes, Google approval prompts, QR verification and Okta push or authenticator approval. Operators can hold a victim on a waiting screen or reject a password.
Lure families include AI ad tools (Muse Ads, ChatGPT Monday Brief, Gemini Ads with manager/MCC account support, Claude Ads Portal, Perplexity campaign planning, Manus), refund and payment-confirmation pages, and recruitment lures (Tesla, Louis Vuitton, Adidas, Nike, Adecco, Robert Half and others). Operators registered a Muse Ads domain on September 16, 2026, eight days after Meta launched its Muse consumer agent. Island saw hundreds of victim submissions and the campaign was still active at publication on October 6, 2026.
The operators exposed earlier versions of the platform through misconfigured public GitHub repositories (recruiterid/teslanewnewne, recruiterid/newnewtesla, and reudisace builds), which confirmed the same routes, the same three-password retry model and Telegram control. Island reports that aged Google Ads accounts are sold on Telegram at $200 to $270 and manager accounts at 2 to 4 times the price of new ones, with escrow and warranties, which points to account resale as the monetization path. Exposure of a manager account can reach downstream client ad accounts. No CVE is involved and no named threat actor is attributed.
MITRE ATT&CK techniques used in TL-2026-2977
Defense Evasion
T1036 Masquerading; T1078 Valid Accounts
Credential Access
T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1621 Multi-Factor Authentication Request Generation
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication
Persistence
Execution
Initial Access
T1566 Phishing; T1566.002 Spearphishing Link
Resource Development
T1583.001 Domains; T1583.004 Server; T1583.006 Web Services
Stealth
Impact
Affected products and versions in Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use
- Google — Google Ads / Google accounts (manager accounts)
Vulnerable versions: Accounts without origin-bound passkeys - Meta — Meta Business / Ads accounts
Vulnerable versions: Accounts without origin-bound passkeys - TikTok — TikTok Ads accounts
Vulnerable versions: Accounts without origin-bound passkeys - Okta — Okta SSO tenants
Vulnerable versions: Push/OTP-based MFA
Remediation for Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use
Immediate actions
- Block the listed lure domains and Railway/Render backend hostnames at DNS, proxy and email gateways
- Review Google Ads, Meta Business and TikTok Ads manager/partner/user lists for unauthorized additions and revoke unknown access
- Reset credentials and revoke sessions for any user who entered credentials after clicking a Connect button on an AI ads tool
- Hunt proxy/DNS logs for Socket.IO connections to up.railway.app or onrender.com hosts from non-developer endpoints
Workarounds
- Access AI ad beta programs only through official vendor sites, not through emailed or messaged links
- Drag the popup window outside the page frame; a BitB window cannot leave the page
Longer-term hardening
- Enforce origin-bound passkeys or hardware security keys for ad platform and SSO (Okta) accounts
- Restrict manager-account (MCC) administrator rights and require approval for new partner links
- Train ad ops and agency staff that real OAuth windows can be verified only from the actual browser origin, and that fake popups can be rendered inside a page
- Alert on unexpected campaign, spend or payment-profile changes
Weaknesses (CWE) in Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use
Timeline of Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use
- Browser-in-the-Browser technique devised by researcher mr.d0x in March 2022; the technique later became the basis for this campaign's fake OAuth windows.
- Earliest sighting of a Tesla recruitment phishing page on the same backend family (July 2025), indicating the platform predates the AI-ads lures.
- Shared Railway backend backend-production-6d75.up.railway.app first scanned; 73 scans across 25 lure domains observed between May 27 and June 20 (Island).
- Last of the observed May 27 - June 20 scans of the shared Railway backend serving 25 lure domains (Island).
- Meta launches its Muse consumer agent in the US, giving operators a new brand to impersonate.
- Operators register the Muse Ads phishing domain (museads.ai) eight days after Meta's Muse launch and stand up the museadsback Railway backend.
- Island publishes 'Behind the Connect Button: The Fake AI Ads Campaign'; BleepingComputer reports on it the same day.
- Island documents earlier platform versions exposed in misconfigured public GitHub repositories (recruiterid/teslanewnewne, recruiterid/newnewtesla), confirming Socket.IO routes and the three-password retry model.
- Island observes hundreds of victim submissions to the platform, whose Telegram control channel is used for operator commands; activity is ongoing at time of writing.
- The Hacker News, The Register and Cyber Security News report the campaign following Island's publication.
Update history for TL-2026-2977
- 2026-10-10 — Fake ChatGPT, Claude and Gemini Advertising Portals Used in Operator-Guided Browser-in-the-Browser Phishing to Steal Passwords and MFA Codes: What changed No severity, exploitability or status change; existing HIGH / ACTIVE values stand. New indicators (11) 11 new domains: additional Claude, ChatGPT, Perplexity and Manus lure domains, a refund-lane domain, four recruitment-lure d
- 2026-10-06 — Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes via Browser-in-the-Browser Phishing: What changed No severity or exploitability change; both remain HIGH / ACTIVE. Record is extended with additional infrastructure and context. New indicators (11) 7 new domains (claude-ads.ai, openai-ads.ai, three refund-lane domains, two Ren
Sources cited for Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use
- Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes (BleepingComputer)
- Behind the Connect Button: The Fake AI Ads Campaign (Island)
- Fake ChatGPT Gemini Sites Steal MFA Codes (CyberUpdates365)
- Fake AI Ad Tools Use Browser-in-the-Browser Phishing to Steal Google and Okta MFA (WindowsForum)
- Exemplifying Emerging Phishing: QR-based Browser-in-The-Browser (BiTB) Attack (arXiv)
- Meta releases Muse Spark, reboots consumer AI push
Detection coverage for TL-2026-2977
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2977 across Splunk SPL, Microsoft KQL and Sigma, covering 54 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.