ChatGPT, Gemini and Claude imitated in fake ads that steal credentials and MFA codes
- Fake AI Marketing Tools Impersonate ChatGPT, Gemini, Claude and Others to Steal Business Accounts
- Attackers use realistic in-browser phishing and live operators to capture credentials
- Stolen advertising accounts provide access to payment methods, quotes, and linked customer accounts.
Cybercriminals are offering fake AI-based products to advertisers and marketing managers, in an attempt to steal their Google business accounts.
Most of the biggest names in AI today, including Chat-GPT, Google Gemini, Claude, Manus, and Muse, are being abused in this campaign, and people are still falling for it.
Island security researchers have published a new report detailing how the campaign works. The operators apparently left source code for earlier versions of their work open in a poorly configured public GitHub repository, giving researchers unique insight into the operation and its success.
Latest videos ofTechnologyRadar
What researchers found was an advanced phishing platform being used to target advertisers and marketing managers. It was used to create websites that offered fake marketing-related products powered by Artificial Intelligence.
“Each brand has its own pitch. ChatGPT promises a Google Ads overview on Mondays. Gemini promises MCC (manager account) and support for linked clients. Claude gets his own advertising portal, Perplexity offers campaign planning and spend audits, and Manus offers a private Meta integration,” the researchers explained.
All about connecting
Each site asked the victim to do the same thing: connect their Google account. After pressing “connect”, the platform launches a typical browser-in-browser (BitB) attack: it displays a complete browser, address bar and all, inside the actual browser.
Therefore, victims who do not pay attention to the details could see a legitimate domain in their address bar, for example accounts.google.com. However, if they looked up a few inches higher, they would see the real domain, which has nothing to do with Google, OpenAI, or any other legitimate business.
The phishing kit is also advanced. The fake browser adapts to whatever the visitor is running, so it won’t happen that a victim running macOS will suddenly see a Windows window. Newer versions also come with nifty little touches, like Safari’s URL pill, Chrome’s custom tabs, and even a dark mode.
When the victim attempts to log in, a “human operator” (the scammer) on the other end follows them through the process. They see each submission and decide what the victim sees next. They can fake a misspelled password error or they can choose which MFA screen they see. The device is fingerprinted, from IP and location, to screen size and WebGL.
The platform was said to support Google, Meta, TikTok, and Okta workflows.
Target advertisers
At the end of the day, it’s all about money. Island says criminals deliberately target merchant accounts because they are connected to credit cards, which they can then abuse.
“The lures are written for agency staff, media buyers, and manager account administrators, because an advertising account is a spending account. It carries a stored payment method and an approved budget, and a manager account can reach multiple client accounts, each with its own billing profile and linked users.”
This is nothing new. Both Google and Facebook have their own ad networks and serve ads to billions of people every day. However, getting accounts, payment methods, and ads approved is a strict and thorough process, so it’s much easier for criminals to simply use someone else’s account, especially if that person has already walked through Google’s fire barefoot.
Unfortunately, Island was unable to disrupt the operation or shoot it down. At the time of writing, the campaign was still ongoing and researchers saw “hundreds of victim submissions to the platform.”
Researchers urge organizations to treat dummy AI integrations like account access requests, inspect the most external source, correlate the customer pattern, and look for the control vocabulary. Finally, they should use phishing-resistant authentication and review changes to advertising control.
“Origin-bound access keys and hardware-backed authentication eliminate the reusable password and one-time code material that this platform is designed to collect,” they said. “After exposure, check each customer account the identity may reach for new administrators or partners, changed recovery details, and campaigns or expenses that no one has approved.”
Through Hacker News
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment