Fake AI Marketing Sites Put a Browser Inside Your Browser to Steal Logins

Fake AI marketing sites impersonating ChatGPT, Gemini, Claude and Muse are stealing ad-account credentials and MFA codes through live phishing flows.

Oct 7, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The login window looks real. The browser around it is not.

Researchers at browser security firm Island uncovered a phishing platform posing as advertising products for ChatGPT, Gemini, Claude, Perplexity, Manus and, more recently, Meta’s Muse. The fake services promise campaign planning, spend audits, Google Ads briefs and other tools aimed at advertisers.

The latest lure, Muse Ads, appeared Sept. 16, just eight days after Meta introduced Muse. Island said the operators simply added a new brand to an existing phishing platform rather than building a new attack from scratch.

“Each product was built around the same action: Connect,” Island researchers Oleg Zaytsev and Ofek Ronen said. That button starts a fake login experience designed to capture credentials and MFA information.

The browser window is the trap

The campaign uses a technique called Browser-in-the-Browser, which places a convincing fake browser window inside the real browser. The imitation can display trusted addresses such as accounts.google.com or an Okta tenant while the actual browser remains on the attacker's domain.

Island said the interface adapts to Windows, macOS, iOS and Android, including dark mode and mobile-browser styling.

But there is a more serious twist: A human operator can control the authentication process while the victim is still on the page. Island said the platform can retain multiple password attempts, request SMS or authenticator codes, trigger Google approval prompts, display QR codes and send Okta push requests. Operators can also reject submitted codes and ask victims to try again.

“Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next,” the researchers said.

Why advertising accounts are worth stealing

The targets include agency employees, media buyers and manager-account administrators because one compromised advertising account can provide access to spending authority and multiple client environments.

Island cited Mimecast research showing that stolen advertising accounts can be used to run fraudulent campaigns or sold in underground markets. Recovering an account can also be harder than canceling a compromised payment card because attackers may add their own administrators and change account permissions. 

Advertisement

That makes the attack more than a credential-theft problem. A compromised manager account could expose several clients at once.

Island also linked the AI-themed pages to fake refund and recruitment sites through shared code, API endpoints and hosting infrastructure. Researchers found older versions in misconfigured public GitHub repositories, helping connect the campaigns to the same underlying phishing framework.

The researchers also found older versions of the platform in misconfigured public GitHub repositories. The exposed code helped connect the different campaigns and showed how the operators reused the same authentication machinery for different victims. 

Island observed hundreds of victim submissions through the campaign's control infrastructure, although that does not mean hundreds of accounts were successfully compromised.

The weakness is the login flow

The attack does not need to compromise Google, Meta or Okta directly. It only needs to convince a victim to authenticate through the wrong page.

New AI products create a useful lure because users may expect unfamiliar integrations to appear soon after launch. Island said the fake Muse service appeared within days of Meta introducing the real product.

That also makes traditional MFA less reassuring in this scenario. A one-time code can still be stolen if the victim types it into an attacker-controlled page while a human attacker is waiting to use it. Phishing-resistant passkeys and hardware-backed authentication are stronger defenses because they bind authentication to the legitimate site rather than simply asking users to prove they know a password or possess a code.

Advertisement

What users should do

Treat any unexpected AI service asking to “connect” a Google, Meta, TikTok or Okta account as an account-access request, not a harmless integration.

Check the browser's actual address bar rather than an address displayed inside a page. Users can also test suspicious login windows by trying to move or resize them; a fake browser window rendered inside a webpage cannot behave like a genuine browser window.

Organizations should review advertising accounts for unfamiliar administrators, partners, recovery changes and campaigns after suspected exposure. If credentials or MFA codes were entered, identity and advertising administrators should reset access and review connected accounts immediately.

The broader risk is not limited to ad spending. The same phishing machinery can target work identities through recruitment lures, potentially turning one stolen Google or Okta login into a path to corporate email, files and other business services.

Other news: Progress patched four Telerik Fiddler Classic vulnerabilities, including a high-severity flaw that could let a low-privilege local attacker execute unintended code with administrator privileges.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.