The login window looks real. The browser around it is not.
Researchers at browser security firm Island uncovered a phishing platform posing as advertising products for ChatGPT, Gemini, Claude, Perplexity, Manus and, more recently, Meta’s Muse. The fake services promise campaign planning, spend audits, Google Ads briefs and other tools aimed at advertisers.
The latest lure, Muse Ads, appeared Sept. 16, just eight days after Meta introduced Muse. Island said the operators simply added a new brand to an existing phishing platform rather than building a new attack from scratch.
“Each product was built around the same action: Connect,” Island researchers Oleg Zaytsev and Ofek Ronen said. That button starts a fake login experience designed to capture credentials and MFA information.
The browser window is the trap
The campaign uses a technique called Browser-in-the-Browser, which places a convincing fake browser window inside the real browser. The imitation can display trusted addresses such as accounts.google.com or an Okta tenant while the actual browser remains on the attacker's domain.
Island said the interface adapts to Windows, macOS, iOS and Android, including dark mode and mobile-browser styling.
But there is a more serious twist: A human operator can control the authentication process while the victim is still on the page. Island said the platform can retain multiple password attempts, request SMS or authenticator codes, trigger Google approval prompts, display QR codes and send Okta push requests. Operators can also reject submitted codes and ask victims to try again.
“Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next,” the researchers said.
Why advertising accounts are worth stealing
The targets include agency employees, media buyers and manager-account administrators because one compromised advertising account can provide access to spending authority and multiple client environments.
Island cited Mimecast research showing that stolen advertising accounts can be used to run fraudulent campaigns or sold in underground markets. Recovering an account can also be harder than canceling a compromised payment card because attackers may add their own administrators and change account permissions.
That makes the attack more than a credential-theft problem. A compromised manager account could expose several clients at once.
Island also linked the AI-themed pages to fake refund and recruitment sites through shared code, API endpoints and hosting infrastructure. Researchers found older versions in misconfigured public GitHub repositories, helping connect the campaigns to the same underlying phishing framework.
The researchers also found older versions of the platform in misconfigured public GitHub repositories. The exposed code helped connect the different campaigns and showed how the operators reused the same authentication machinery for different victims.
Island observed hundreds of victim submissions through the campaign's control infrastructure, although that does not mean hundreds of accounts were successfully compromised.
The weakness is the login flow
The attack does not need to compromise Google, Meta or Okta directly. It only needs to convince a victim to authenticate through the wrong page.
New AI products create a useful lure because users may expect unfamiliar integrations to appear soon after launch. Island said the fake Muse service appeared within days of Meta introducing the real product.
That also makes traditional MFA less reassuring in this scenario. A one-time code can still be stolen if the victim types it into an attacker-controlled page while a human attacker is waiting to use it. Phishing-resistant passkeys and hardware-backed authentication are stronger defenses because they bind authentication to the legitimate site rather than simply asking users to prove they know a password or possess a code.
What users should do
Treat any unexpected AI service asking to “connect” a Google, Meta, TikTok or Okta account as an account-access request, not a harmless integration.
Check the browser's actual address bar rather than an address displayed inside a page. Users can also test suspicious login windows by trying to move or resize them; a fake browser window rendered inside a webpage cannot behave like a genuine browser window.
Organizations should review advertising accounts for unfamiliar administrators, partners, recovery changes and campaigns after suspected exposure. If credentials or MFA codes were entered, identity and advertising administrators should reset access and review connected accounts immediately.
The broader risk is not limited to ad spending. The same phishing machinery can target work identities through recruitment lures, potentially turning one stolen Google or Okta login into a path to corporate email, files and other business services.
Other news: Progress patched four Telerik Fiddler Classic vulnerabilities, including a high-severity flaw that could let a low-privilege local attacker execute unintended code with administrator privileges.





