Cybersecurity

Fake ChatGPT and Gemini Sites Steal Advertising Accounts and Multi-Factor Authentication Codes

Researchers identified a phishing campaign exploiting fake sites for ChatGPT, Gemini, Claude, and Perplexity to target advertising account managers and steal login credentials and MFA codes through fake browser windows. The operation uses reusable technical infrastructure and supports login flows for Google, Meta, TikTok, and Okta.

2026-10-06
3 min read
0 views
certi.news Editorial Team
Fake ChatGPT and Gemini Sites Steal Advertising Accounts and Multi-Factor Authentication Codes

Researchers from browser security company Island identified a phishing campaign targeting advertising agency employees, media buyers, and account managers through sites impersonating ChatGPT, Gemini, Claude, and Perplexity. These pages target accounts that typically allow the management of budgets and campaigns for multiple clients, giving attackers an opportunity to spend the balances on fraudulent campaigns or resell the accounts to cybercriminals.

The campaign links AI tools to advertising work scenarios; the fake sites claim to help users reach buyers, obtain advertising briefs, and plan and review campaigns and spending. However, the “Connect” button does not open a genuine login process. Instead, it displays a fake Google window inside the page, with an address bar suggesting that it is connected to the accounts.google.com domain.

How Does the Fake Browser Window Work?

The operation relies on the Browser-in-the-Browser technique, in which the malicious page creates a window resembling the original login window inside the browser, using fake interface elements, an address bar, and a link. The window is actually an iframe designed to collect the victim’s data, not a genuine OAuth window that can be separated from the page.

According to the researchers, the phishing tool adapts to Windows, macOS, iOS, and Android, and also supports different display modes, including dark mode. After the flow begins, a human operator can control the next steps, including requesting the password up to three times, requesting a code delivered by text message or an authenticator app, or displaying Okta Push requests, Google consent prompts, and QR codes.

The operator can also reject codes entered by victims, keep the process on a waiting screen, or terminate and hide the flow at any time. The researchers found that the platform supports login paths for Google, Meta, TikTok, and Okta, and that control commands are sent through Socket.IO events.

Indicators of a Larger Operation

Infrastructure analysis showed that the campaign is part of a larger operation using multiple lures, including fake job offers and pages for recovering money. The pages linked to the operation share the use of Next.js and Socket.IO, as well as similar API endpoints, while many of them rely on Vercel-hosted backends hosted on Railway or Render.

The researchers were able to trace the activity back to March after finding old source code exposed in improperly configured public GitHub repositories. The Telegram control channel also received hundreds of victim records, although this figure does not prove how many accounts were actually compromised.

What Should You Watch For?

The campaign demonstrates that an AI tool appearing as the front end does not mean that the login process is secure or authentic. Practical indicators of a browser-in-the-browser window include being unable to move it outside the browser window or resize it, functions that are normally available in genuine OAuth windows. The researchers also point out that the platform does not rely on a transparent reverse proxy. Instead, it rebuilds the service provider’s interface locally and collects login data and MFA status through its own interfaces, making network traffic appear to be a connection between an AI product and an unrelated backend service.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news