Fake ChatGPT and Gemini sites hijack ad accounts with live browser-in-the-browser phishing
Island researchers found fake AI product sites that lure advertising staff into a fake Google sign-in window, where a human operator harvests passwords and MFA codes in real time.
At a glance
- Fake sites impersonating ChatGPT, Gemini, Claude and Perplexity target agency staff, media buyers and ad account administrators.
- A browser-in-the-browser window imitating accounts.google.com collects credentials while a live operator requests SMS, authenticator, Okta push or QR codes.
- The kit supports Google, Meta, TikTok and Okta sign-in flows; its Telegram channel received hundreds of victim submissions.
- Island says exposed GitHub repositories trace the operation back to March.
A phishing operation is using fake websites that pose as ChatGPT, Gemini, Claude and Perplexity to steal advertising account credentials and multi-factor authentication (MFA) codes, according to research by browser security company Island reported by BleepingComputer on October 6. The campaign targets agency staff, media buyers and ad account administrators, people whose accounts often reach many downstream client accounts and carry spending authority.
What happened
According to BleepingComputer, the phishing pages present themselves as AI products that help advertisers reach buyers, obtain ad briefs and plan campaigns. Visitors are prompted to press a "Connect" button to link their accounts. The operator also used Meta's recent launch of its Muse AI agent as a lure, and Island observed dozens of URLs used for campaigns themed around ads, refunds and recruitment.
The report notes that compromised advertising accounts are valuable to criminals because available balances can be spent on fraudulent ads or the accounts can be resold.
Technical details
When a victim clicks "Connect", a fake Google login window appears inside the real browser page, complete with a title bar and an address bar showing accounts.google.com. This browser-in-the-browser (BitB) window is actually an iframe built to harvest credentials. Island said a human operator then takes over the session and can ask for the password several times, request SMS or authenticator codes, display Okta push requests, Google approval prompts or QR codes, reject submitted codes, hold the victim on waiting screens or end the flow at any point.
The researchers said the platform supports Google, Meta, TikTok and Okta sign-in workflows through Socket.IO events. Campaigns share a common stack built on Next.js and Socket.IO, shared API endpoints, and Vercel-hosted front ends with Railway or Render back ends. Unlike a transparent reverse-proxy kit, the platform rebuilds the provider interface locally and collects credentials and MFA state through its own APIs, Island said. The kit also adapts its interface to Windows, macOS, iOS and Android, including browser styling and dark mode.
A Telegram control channel tied to the operation received "hundreds of victim submissions", according to Island, though the company noted this does not necessarily mean the same number of accounts were successfully compromised. Misconfigured public GitHub repositories exposed older source code, allowing the researchers to trace activity back to March. The number of hijacked accounts has not been independently verified.
What to do
Island pointed out that BitB windows can be spotted: a genuine OAuth pop-up is a real browser window that can be dragged and resized outside the page, while an iframe-based fake cannot leave the browser window. Advertising teams should treat "connect your account" prompts on unfamiliar AI tools with suspicion, verify domains before signing in, and prefer phishing-resistant MFA such as passkeys or hardware security keys over SMS and one-time codes, which a live operator can relay. Organizations managing client ad accounts should also review sign-in alerts and unexpected spending on those accounts.
Sources
- Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes — BleepingComputer
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



