Threat reportPhishingTL-2026-2977

Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use Browser-in-the-Browser Phishing to Steal Ad Account Credentials and MFA Codes

highACTIVE

Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use (TL-2026-2977), also tracked as The Fake AI Ads Campaign, is a high-severity phishing campaign, first published 2026-10-06 and last reviewed 2026-10-10. It has no confirmed attribution, affects Google Google Ads / Google accounts (manager accounts), maps to 16 MITRE ATT&CK techniques (T1036, T1056.003, T1071.001), and is covered by 9 detection rules and 54 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
54Indicators of compromise

Key facts for TL-2026-2977

Threat ID
TL-2026-2977
Also known as
The Fake AI Ads Campaign, Behind the Connect Button
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
advertising, marketing agencies, media buying, ecommerce, technology
Target regions
Global
Detection rules
9
Indicators of compromise
54
Updates
2026-10-10 · 2 updates · revalidated 2× · latest source

Malware and tooling in Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use

Malware and tooling: Telegram

How Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use works

A human-operated phishing platform impersonates AI advertising products (ChatGPT, Gemini, Claude, Perplexity, Manus and, newest, Meta Muse Ads) and presents a fake OAuth popup via Browser-in-the-Browser (BitB) to harvest Google, Meta, TikTok and Okta credentials and MFA codes. Operators steer each victim through MFA challenges in real time over Socket.IO and a Telegram control channel, targeting agency staff, media buyers and manager-account administrators.

Island researchers documented a phishing platform presented as a portfolio of AI advertising products. Every lure is built around a single 'Connect' button. Clicking it opens a browser window drawn inside the page (Browser-in-the-Browser), with a fake address bar showing accounts.google.com or an Okta tenant while the real browser stays on the phishing domain. The fake window imitates Safari's URL pill, Chrome custom tabs and a dark mode, with translucent iOS toolbar styling so it does not look painted on.

The stack is a Next.js frontend (hosted on Vercel) talking over Socket.IO to a backend on Railway or Render. The backend keeps every password attempt (password_one, password_two, password_three), fingerprints the device (IP, geolocation through ipify/ipapi.co, screen size, WebGL capabilities) and lets a human operator pick the next MFA challenge the victim sees. Operator directives follow an authentication state machine (/password, /2fa, /authApp, /googlePrompt, /googleQrVerify, /verifyTap, /oktaApprove, /oktaAuthApp, /wrong2fa, /done, /ban), carried on the operator-command and telegram-command Socket.IO events. The platform handles SMS and authenticator codes, Google approval prompts, QR verification and Okta push or authenticator approval. Operators can hold a victim on a waiting screen or reject a password.

Lure families include AI ad tools (Muse Ads, ChatGPT Monday Brief, Gemini Ads with manager/MCC account support, Claude Ads Portal, Perplexity campaign planning, Manus), refund and payment-confirmation pages, and recruitment lures (Tesla, Louis Vuitton, Adidas, Nike, Adecco, Robert Half and others). Operators registered a Muse Ads domain on September 16, 2026, eight days after Meta launched its Muse consumer agent. Island saw hundreds of victim submissions and the campaign was still active at publication on October 6, 2026.

The operators exposed earlier versions of the platform through misconfigured public GitHub repositories (recruiterid/teslanewnewne, recruiterid/newnewtesla, and reudisace builds), which confirmed the same routes, the same three-password retry model and Telegram control. Island reports that aged Google Ads accounts are sold on Telegram at $200 to $270 and manager accounts at 2 to 4 times the price of new ones, with escrow and warranties, which points to account resale as the monetization path. Exposure of a manager account can reach downstream client ad accounts. No CVE is involved and no named threat actor is attributed.

MITRE ATT&CK techniques used in TL-2026-2977

Defense Evasion

T1036 Masquerading; T1078 Valid Accounts

Credential Access

T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1621 Multi-Factor Authentication Request Generation

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication

Persistence

T1098 Account Manipulation

Execution

T1204.001 Malicious Link

Initial Access

T1566 Phishing; T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.004 Server; T1583.006 Web Services

Stealth

T1656 Impersonation

Impact

T1657 Financial Theft

Affected products and versions in Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use

  • Google — Google Ads / Google accounts (manager accounts)
    Vulnerable versions: Accounts without origin-bound passkeys
  • Meta — Meta Business / Ads accounts
    Vulnerable versions: Accounts without origin-bound passkeys
  • TikTok — TikTok Ads accounts
    Vulnerable versions: Accounts without origin-bound passkeys
  • Okta — Okta SSO tenants
    Vulnerable versions: Push/OTP-based MFA

Remediation for Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use

Immediate actions

  • Block the listed lure domains and Railway/Render backend hostnames at DNS, proxy and email gateways
  • Review Google Ads, Meta Business and TikTok Ads manager/partner/user lists for unauthorized additions and revoke unknown access
  • Reset credentials and revoke sessions for any user who entered credentials after clicking a Connect button on an AI ads tool
  • Hunt proxy/DNS logs for Socket.IO connections to up.railway.app or onrender.com hosts from non-developer endpoints

Workarounds

  • Access AI ad beta programs only through official vendor sites, not through emailed or messaged links
  • Drag the popup window outside the page frame; a BitB window cannot leave the page

Longer-term hardening

  • Enforce origin-bound passkeys or hardware security keys for ad platform and SSO (Okta) accounts
  • Restrict manager-account (MCC) administrator rights and require approval for new partner links
  • Train ad ops and agency staff that real OAuth windows can be verified only from the actual browser origin, and that fake popups can be rendered inside a page
  • Alert on unexpected campaign, spend or payment-profile changes

Weaknesses (CWE) in Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use

CWE-1021, CWE-451

Timeline of Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use

  • Browser-in-the-Browser technique devised by researcher mr.d0x in March 2022; the technique later became the basis for this campaign's fake OAuth windows.
  • Earliest sighting of a Tesla recruitment phishing page on the same backend family (July 2025), indicating the platform predates the AI-ads lures.
  • Shared Railway backend backend-production-6d75.up.railway.app first scanned; 73 scans across 25 lure domains observed between May 27 and June 20 (Island).
  • Last of the observed May 27 - June 20 scans of the shared Railway backend serving 25 lure domains (Island).
  • Meta launches its Muse consumer agent in the US, giving operators a new brand to impersonate.
  • Operators register the Muse Ads phishing domain (museads.ai) eight days after Meta's Muse launch and stand up the museadsback Railway backend.
  • Island publishes 'Behind the Connect Button: The Fake AI Ads Campaign'; BleepingComputer reports on it the same day.
  • Island documents earlier platform versions exposed in misconfigured public GitHub repositories (recruiterid/teslanewnewne, recruiterid/newnewtesla), confirming Socket.IO routes and the three-password retry model.
  • Island observes hundreds of victim submissions to the platform, whose Telegram control channel is used for operator commands; activity is ongoing at time of writing.
  • The Hacker News, The Register and Cyber Security News report the campaign following Island's publication.

Update history for TL-2026-2977

Sources cited for Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use

Detection coverage for TL-2026-2977

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2977 across Splunk SPL, Microsoft KQL and Sigma, covering 54 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
54 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats