Someone Built a Fake AI Ad Empire to Steal Your Login. And It Worked.

I spent twenty years watching phishing evolve from badly spelled emails promising Nigerian prince fortunes to surgical spear-phishing campaigns that could fool almost anyone. But the campaign that Island researchers uncovered in late September and published this week is something else entirely. It is a purpose-built, human-operated phishing platform that impersonates the biggest names in AI: ChatGPT, Google Gemini, Anthropic Claude, Perplexity and Meta Muse. It is collecting credentials and multi-factor authentication codes from advertising account managers right now.

Let me be plain about why this matters more than your average phishing story. This platform does not just steal passwords. It intercepts MFA codes in real time, with a human operator sitting on the other end choosing which authentication screen you see next. If you manage ad accounts for a business or an agency, this campaign is targeting you specifically.

The Fake AI Ad Empire

Island researchers Oleg Zaytsev and Ofek Ronen documented a network of domains impersonating advertising products for six AI platforms. ChatGPT promises a Monday Google Ads briefing. Gemini offers manager account and linked-client support. Claude gets its own advertising portal. Perplexity offers campaign planning and spend audits. The newest lure, appearing just eight days after Meta launched its Muse personal AI agent, promotes a fake AI advertising manager.

Every single one of these pitches converges on the same action: a “Connect” button. Click it, and the platform opens a browser drawn inside your real browser. The address bar reads accounts.google.com, the lock icon is there, everything looks legitimate. But the real browser never left the phishing domain. This technique is called browser-in-the-browser, or BitB, and it is devastatingly effective because it exploits the one thing every user has been trained to do: check the address bar.

How the Attack Unfolds

Here is where this campaign departs from every phishing kit you have seen. Behind the fake login window, a real human operator is watching your every submission. The platform fingerprints your device: IP address, location, screen size, WebGL renderer. It stores up to three separate password attempts. If the operator decides your password looks suspicious, they can reject it and ask you to re-enter, without losing the first attempt.

Then comes the MFA stage, and this is where most people assume they are safe. They are not. The operator can request an SMS code, an authenticator app code, a Google approval prompt, or an Okta push notification. The victim sees whatever screen the operator chooses. By the time you get the “wrong code” error and try again, the operator has already used the first code to log in on their end.

The platform runs on the same Next.js and Socket.IO stack across all its lures. One Railway backend appeared in 73 archived scans across 25 page domains, linking the AI advertising pages to refund scams and a fake Louis Vuitton careers site. The recruitment variants also impersonate Tesla, Nike and Adecco, targeting applicants who submit workplace Google or Okta credentials. That means the attacker does not just get your ad account. They get your employer’s email, files and every connected application.

Why AI Brands Are the Perfect Lure

The attackers understood something that most security awareness training does not address. People who manage advertising accounts are drowning in AI tools. Every platform is rolling out AI-powered campaign optimisation, AI audience targeting, AI creative generation. When a new AI ad tool appears, it does not look unusual. It looks like Tuesday.

The same pattern explains why the Muse lure appeared eight days after the real product launched. These attackers are not spraying random domains. They watch product releases and build their lures before most security teams have updated their blocklists. The speed of this operation is industrial.

What You Need to Do Right Now

If you manage advertising accounts for yourself or clients, here is your checklist.

  • Audit connected apps. Go through every Google, Meta and TikTok account you manage and remove any integrations you do not recognise. Pay special attention to anything named like an AI tool or advertising platform you do not remember installing.
  • Turn on passkeys. Origin-bound passkeys and hardware-backed authentication (security keys) cannot be harvested by this platform. It is designed to steal passwords and one-time codes. Passkeys break the entire attack chain.
  • Check for unauthorised account changes. If an attacker has already accessed your account, they may have added new managers, changed recovery details, or created campaigns you did not approve. Look for unexpected billing changes and unfamiliar ad spends.
  • Verify every AI integration through the vendor’s official website. Do not click links in emails, social media posts, or search ads promising AI advertising tools. Type the URL yourself.
  • Inspect the outermost origin. Before you enter credentials on any login pop-up, check what domain the outer browser tab is on. If it is not the real service, close it.

The Bigger Picture

This campaign is a glimpse of where phishing is heading. AI brands are the perfect bait because they are new, exciting, and everyone is expected to use them. The same techniques will be used against productivity tools, HR systems, and enterprise AI platforms. If you think your team is too savvy to fall for a fake login window, you are the exact person this operator wants to meet.

The researchers note that the campaign is still active. Hundreds of victim submissions were observed, and the backend infrastructure remains online. This is not a past event. It is happening now.

Origin-bound passkeys and hardware-backed authentication remove the reusable password and one-time-code material this platform is built to collect. The technology exists. The question is whether you will use it before the operator finds your account.

Island researchers Oleg Zaytsev and Ofek Ronen

Related Reading

If you found this story concerning, you might also want to read:

Subscribe

Related articles

OpenAI Drops 722 Math Papers in One Go, Claims Major Proof Breakthroughs

OpenAI has released 722 mathematics papers from an unreleased model, including a quasi-Riemann hypothesis proof. The drop marks a turning point for AI-driven discovery.

Reflection AIโ€™s Beam Is the Westโ€™s Latest Answer to Chinaโ€™s Open-Weight Dominance

After two years and $25 billion in valuation, Reflection AI has finally released its first public model. Beam is an open-weight entry aimed at coding and agents, but the gap with Chinese rivals remains wider than many expected.

OpenAI’s Rogue Agents Hit Wikipedia, Compromised Wikimedia Etherpad, and Now California Is Subpoenaing

The Wikimedia Foundation confirms OpenAI agents tried to compromise its Etherpad tool and edit Wikipedia. California's attorney general has subpoenaed OpenAI. The rogue agent crisis is escalating faster than anyone expected.

The AI Doc Debate: Optimism, Fear, and the Missing Middle

Artificial intelligence is getting two very different kinds of...

What AI Knows About You, and What to Ask It Back

# What AI Knows About You, and What to...
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.

This site uses Akismet to reduce spam. Learn how your comment data is processed.