# Fake ChatGPT/Gemini/Claude Ad-Tool Lure Sites Use Browser-in-the-Browser Phishing to Steal Ad Account Credentials and MFA Codes

> A human-operated phishing platform impersonates AI advertising products (ChatGPT, Gemini, Claude, Perplexity, Manus and, newest, Meta Muse Ads) and presents a fake OAuth popup via Browser-in-the-Browser (BitB) to harvest Google, Meta, TikTok and Okta credentials and MFA codes. Operators steer each victim through MFA challenges in real time over Socket.IO and a Telegram control channel, targeting agency staff, media buyers and manager-account administrators.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-10T12:31:35.052Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2977
- **ID:** TL-2026-2977
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 54 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Island researchers documented a phishing platform presented as a portfolio of AI advertising products. Every lure is built around a single 'Connect' button. Clicking it opens a browser window drawn inside the page (Browser-in-the-Browser), with a fake address bar showing accounts.google.com or an Okta tenant while the real browser stays on the phishing domain. The fake window imitates Safari's URL pill, Chrome custom tabs and a dark mode, with translucent iOS toolbar styling so it does not look painted on.

The stack is a Next.js frontend (hosted on Vercel) talking over Socket.IO to a backend on Railway or Render. The backend keeps every password attempt (password_one, password_two, password_three), fingerprints the device (IP, geolocation through ipify/ipapi.co, screen size, WebGL capabilities) and lets a human operator pick the next MFA challenge the victim sees. Operator directives follow an authentication state machine (/password, /2fa, /authApp, /googlePrompt, /googleQrVerify, /verifyTap, /oktaApprove, /oktaAuthApp, /wrong2fa, /done, /ban), carried on the operator-command and telegram-command Socket.IO events. The platform handles SMS and authenticator codes, Google approval prompts, QR verification and Okta push or authenticator approval. Operators can hold a victim on a waiting screen or reject a password.

Lure families include AI ad tools (Muse Ads, ChatGPT Monday Brief, Gemini Ads with manager/MCC account support, Claude Ads Portal, Perplexity campaign planning, Manus), refund and payment-confirmation pages, and recruitment lures (Tesla, Louis Vuitton, Adidas, Nike, Adecco, Robert Half and others). Operators registered a Muse Ads domain on September 16, 2026, eight days after Meta launched its Muse consumer agent. Island saw hundreds of victim submissions and the campaign was still active at publication on October 6, 2026.

The operators exposed earlier versions of the platform through misconfigured public GitHub repositories (recruiterid/teslanewnewne, recruiterid/newnewtesla, and reudisace builds), which confirmed the same routes, the same three-password retry model and Telegram control. Island reports that aged Google Ads accounts are sold on Telegram at $200 to $270 and manager accounts at 2 to 4 times the price of new ones, with escrow and warranties, which points to account resale as the monetization path. Exposure of a manager account can reach downstream client ad accounts. No CVE is involved and no named threat actor is attributed.

## MITRE ATT&CK

- T1583.001 Domains
- T1583.006 Web Services
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1036 Masquerading
- T1056.003 Web Portal Capture
- T1111 Multi-Factor Authentication Interception
- T1621 Multi-Factor Authentication Request Generation
- T1071.001 Web Protocols
- T1102.002 Bidirectional Communication
- T1078 Valid Accounts
- T1657 Financial Theft
- T1583.004 Server
- T1566 Phishing
- T1656 Impersonation
- T1098 Account Manipulation

## Sources

- [Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes (BleepingComputer)](https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/)
- [Behind the Connect Button: The Fake AI Ads Campaign (Island)](https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign)
- [Fake ChatGPT Gemini Sites Steal MFA Codes (CyberUpdates365)](https://cyberupdates365.com/fake-chatgpt-gemini-sites-phishing/)
- [Fake AI Ad Tools Use Browser-in-the-Browser Phishing to Steal Google and Okta MFA (WindowsForum)](https://windowsforum.com/news/fake-ai-ad-tools-use-browser-in-the-browser-phishing-to-steal-google-and-okta-mfa.447374/)
- [Exemplifying Emerging Phishing: QR-based Browser-in-The-Browser (BiTB) Attack (arXiv)](https://ar5iv.labs.arxiv.org/html/2505.18944)
- [Meta releases Muse Spark, reboots consumer AI push](https://letsdatascience.com/news/meta-releases-muse-spark-reboots-consumer-ai-push-11b99607)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2977
