Cybersecurity researchers have detailed a new 'human-operated phishing platform' that creates fake advertising portals for popular AI chatbots. These include Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The deceptive sites claim to offer services like campaign optimization and ad account connections.
The core of the attack involves the browser-in-the-browser (BitB) trick. When a user clicks a 'Connect' button on the phishing site, a fake browser window appears within the real browser. This fake window displays a spoofed address bar showing trusted origins, such as accounts.google.com or an Okta tenant, while the actual browser remains on the phishing domain. This method is used to capture login credentials and multi-factor authentication (MFA) codes.
Behind the user interface, the platform records every password attempt and fingerprints the victim's device. An operator then selects which MFA challenge the victim sees next. For example, a site like 'museads.ai' emerged shortly after Meta launched its AI agent, Muse, and claimed to be an 'AI ads manager.' Clicking its 'Connect' button initiates a BitB attack to steal credentials for Google, Meta, TikTok, and Okta.
Victim device information is sent to the attacker, and operator commands are exchanged based on the login workflow. With the captured account credentials, the attacker attempts to log into the victim's account in real-time. Each fake brand portal offers a tailored pitch, such as ChatGPT promising Google Ads briefs or Gemini offering MCC support, to entice users.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cybersecurity researchers uncovered a human-operated phishing platform that mimics advertising products for AI chatbots like ChatGPT, Gemini, and Claude. The platform uses browser-in-the-browser (BitB) attacks to capture user credentials and multi-factor authentication codes by displaying fake login windows.