research / browser-in-the-browser-phishing-ai-ads

Browser-in-the-browser phishing targets AI ad account managers

Island found a human-operated phishing platform behind fake ChatGPT, Gemini, and Muse ad portals that steals ad account credentials and MFA codes in real time.

Island's security research team has documented a human-operated phishing platform that impersonates advertising products for ChatGPT, Gemini, Claude, Perplexity, Manus, and Meta's Muse agent. Every fake product ends at the same Connect button. Clicking it opens a browser-in-the-browser phishing window whose address bar reads accounts.google.com or an Okta tenant, while the real browser never leaves the attacker's domain. A live operator then picks which MFA challenge the victim sees next, which makes one-time codes a weak defense against this kit.

One kit, many AI brands

The platform is brand-agnostic. "Each product was built around the same action: Connect," Island researchers Oleg Zaytsev and Ofek Ronen wrote in a report published October 6. Meta announced Muse, a personal AI agent, on September 8, 2026. By September 16, museads.ai was live, pitching Muse Ads as "Your AI ads manager for paid media workflows."

The older skins in the family follow the same shape. ChatGPT promises a Monday Google Ads brief, Gemini offers MCC (manager account) and linked-client support, Claude gets its own advertising portal, Perplexity offers campaign planning and spend audits, and Manus a private Meta integration. The copy uses advertiser shorthand like MCC and ROAS, so a request to connect an account reads as routine work. Targets are agency staff, media buyers, and manager-account administrators, reached through invitation emails.

The infrastructure is shared across three lure lanes: AI ads, payment and refund pages, and recruitment sites for Tesla, Louis Vuitton, Nike, and Adecco. Everything runs on one Next.js and Socket.IO stack, often Vercel-hosted frontends with Railway or Render backends. One backend turned up in 73 archived scans across 25 page domains between May 27 and June 20, serving AI ad lures, refund pages, and a fake Louis Vuitton careers site. The operators also left earlier source code in misconfigured public GitHub repositories. BleepingComputer notes that this lets Island trace the operation back to March. Island says activity was still ongoing at the time of writing.

How the fake browser window works

Clicking Connect does not take the victim to Google. The page draws a fake Chrome or Safari window inside itself, complete with lock icon and address bar, while the real browser stays where it is. The technique, browser-in-the-browser (BitB), was publicized by the researcher mr. dox in March 2022. This kit adapts the fake chrome to Windows, macOS, iOS, and Android, down to frosted iOS toolbars and dark mode.

The architecture is what defeats the usual detections. "Unlike a transparent reverse-proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs," Island writes. The traffic looks like an AI product talking to an application backend.

An operator drives the login in real time

Behind the fake window is a state machine with a human at the wheel. On Connect, the client creates a victim record at /api/create/user, fingerprints the device (IP, location, screen size, WebGL), and sends the profile to /api/send/ip. The state object retains three separate password attempts, so the operator can reject one entry, ask the victim to try again, and keep every submitted value.

Commands arrive as Socket.IO events named operator-command and telegram-command. The vocabulary lets the operator request an SMS or authenticator code, show a Google approval prompt or QR payload, push an Okta approval, reject a submitted code, park the victim on a waiting screen, or suppress the page for that visitor. BleepingComputer reports the Telegram control channel has collected hundreds of victim submissions. That count overstates real compromises, but it shows the throughput. Google, Meta, TikTok, and Okta sign-in workflows are all supported.

Why ad manager accounts are the prize

An advertising account is a spending account. It carries a stored payment method and an approved budget, and a Google Ads manager account can reach several client accounts, each with its own billing profile and linked users. Island, citing Mimecast's ad account theft research, describes two monetization paths: spend the budget on the attacker's own campaigns, or sell the account. Aged accounts with a clean spend history sell for two to four times the price of new ones, and Google Ads accounts in high-risk verticals list at roughly $200 to $270. The Hacker News ties this to Mimecast's July 2026 findings on VietCredCare, DuckTail, NodeStealer, and PXA Stealer turning ad account theft into commodity crime.

Recovery is the expensive part. "For the victim, the card is the easy part: they can remove it within hours. Getting the account back is not," Island writes. Attackers add their own administrators and downgrade the legitimate owner, and recovery can take weeks or months while the account keeps serving ads. For a manager account, the damage reaches the agency's clients.

Detection signals and hardening steps

  • Block and alert on Island's published IOC list. The domains follow obvious patterns (advertising-chatgpt.com, gemini-ads.ai, claude-advertisers.com, mcc-verification.com) and include the Railway and Render backends.
  • Correlate on the client pattern instead of hosting IPs: api.ipify.org, ipapi.co, /api/create/user, /api/send/ip, repeated password fields, and Socket.IO connections to unrelated Railway or Render hosts.
  • Hunt the control event names. operator-command and telegram-command appearing in served JavaScript or proxy logs are strong signals of this specific kit.

On the hardening side, move ad platform and SSO logins to phishing-resistant authentication. Origin-bound passkeys and hardware-backed tokens remove the reusable password and one-time code this platform exists to collect.

Teach the drag test in awareness training. A BitB window is an iframe, so it cannot be dragged outside the browser window or resized, while a real OAuth popup can. Treat any AI "connect your account" beta invite as an access request and verify the program on the vendor's official site. After a suspected exposure, review every client account the identity could reach for new managers or partners, changed recovery details, and spend nobody approved.

Island also documented a related delivery cluster in the same report cycle: Google-sponsored results routing users to custom GPTs and shared chat content that redirect to a fake Cloudflare verification page delivering NetSupport RAT, about 850 paid-ad landings across 26 lookalike destinations over the three months ending August 2026. We covered that pattern when we looked at malicious custom GPTs used as ClickFix lures. "They also move with the news," Island notes, and Muse Ads shipped eight days after Muse. Refresh your blocklists and phishing examples when the next AI product launches. This crew has shown it can have a convincing fake up within a week.

// Drafted with AI assistance from the sources above and published automatically.