Fake AI Sites Use Browser‑in‑the‑Browser to Steal Ad Accounts and MFA Codes
A new campaign uses counterfeit ChatGPT‑style pages to harvest login details and multi‑factor codes from advertising professionals through a deceptive browser‑in‑the‑browser method.
A wave of phishing attacks is using counterfeit AI sites that look like ChatGPT, Gemini, Claude, and Perplexity to steal login credentials and multi‑factor authentication (MFA) codes from advertising professionals. The sites embed a fake browser window inside the page, a technique known as browser‑in‑the‑browser (BitB), to capture credentials as victims think they are signing in to Google, Meta, TikTok, or Okta. Researchers at Island and BleepingComputer say the operation targets agency staff, media buyers, and administrators who manage large ad budgets, allowing attackers to run fraudulent campaigns or resell the accounts.
How the phishing flow works
The fake AI pages advertise themselves as tools that can help advertisers reach buyers, write ad briefs, and audit campaign spend. When a visitor clicks a "Connect" button, a window that looks exactly like a Google login page appears inside the page. The address bar shows "accounts.google.com", but the window is actually an iframe designed to capture whatever the user enters. The BitB technique was first described by researcher mr. dox in 2022 and has been reused for other targets, including gaming accounts.
Once the victim enters a password, the phishing kit can ask for the password up to three times, request an SMS or authenticator code, display Okta push prompts, or even show a QR code. A human operator controls the flow in real time, deciding whether to accept the code, hold it, or abort the session. The platform rebuilds the sign‑in interface locally and sends the captured data through its own APIs, masking the traffic as if it were coming from a legitimate AI product.
Why ad accounts are valuable
Advertising accounts often hold significant balances that can be spent on paid campaigns. When an attacker gains access, they can launch fraudulent ads that drain the budget or sell the compromised account to other criminals. The reports note that the stolen accounts are sometimes resold for “significant amounts,” indicating a secondary market for these credentials. Because many agencies manage multiple downstream client accounts, a single compromised login can expose a chain of budgets and data.
Technical details of the BitB trick
Island researchers found that the phishing kit adapts its look to Windows, macOS, iOS, and Android, including dark‑mode support. The underlying code uses a Next.js front end with Socket.IO for real‑time communication, hosted on Vercel frontends and Railway or Render backends. The same infrastructure also powers other lures in the campaign, such as fake recruitment offers and refund pages. Misconfigured public GitHub repositories revealed older versions of the code, allowing investigators to trace the operation back to March.
The BitB window cannot be moved or resized like a legitimate OAuth popup, which makes it possible to spot the trick. "BitB attacks are deceptive but also easy to uncover," one researcher noted. If the login prompt appears embedded within the page rather than as a separate browser window, users should treat it as suspicious.
Practical steps to protect your team
- Verify the URL in the browser’s address bar before entering credentials. A genuine OAuth flow opens in a new window, not inside the page.
- Use hardware‑based MFA tokens where possible; they are harder for attackers to intercept than SMS or app codes.
- Educate staff that legitimate AI tools will never ask for direct account connections via embedded login frames.
- Restrict admin access to ad platforms and enforce least‑privilege principles. Only grant the permissions needed for daily tasks.
- Monitor for unusual spending patterns on ad accounts and set alerts for large or new campaigns.
- Keep your browsers and extensions up to date to benefit from anti‑phishing protections.
For a quick health check of your own web presence, start with a free external scan. It can highlight exposed login flows and help you prioritize remediation.
By staying aware of the browser‑in‑the‑browser technique and tightening MFA and access controls, organizations can reduce the risk of losing valuable advertising accounts to these AI‑themed phishing scams.
Sources
- Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes BleepingComputer
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.