Threat Intelligence

Fake AI Advertising Portals Use Counterfeit Login Windows to Steal Passwords and MFA Codes

The Hacker News · 7 Oct 2026
Key Takeaway Be wary of any new AI advertising tool that asks you to "Connect" your accounts, and go directly to the official site yourself rather than trusting a sign-in window, even if its address bar looks legitimate.

Researchers at Island have described a "human-operated phishing platform" that impersonates advertising products for AI chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse and Manus. The fake products claim to offer campaign optimisation, spend audits and business-account connections. Their real purpose is to capture passwords and multi-factor authentication (MFA) codes.

Each site is built around a "Connect" button. Clicking it opens what looks like a browser window, but it is actually drawn inside the real browser page, a method known as browser-in-the-browser. The fake address bar can show trusted addresses such as accounts.google.com or an Okta sign-in page, while the real browser stays on the phishing domain. One example, museads.ai, appeared on September 16, 2026, a little over a week after Meta launched its Muse AI agent. It targeted Google, Meta, TikTok and Okta logins.

Behind the scenes, the platform records every password attempt and fingerprints the victim's device. A human operator can then choose which MFA challenge the victim sees next, and tries to sign in to the real account in real time. Researchers noted that each brand gets its own tailored pitch, such as Google Ads briefs for ChatGPT, manager account support for Gemini, and a private Meta integration for Manus.

phishing browser-in-the-browser MFA AI impersonation credential theft

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.