Cybercriminals have been using sophisticated phishing techniques to steal advertising account login credentials and multi-factor authentication (MFA) codes from unsuspecting agency staff, media buyers, and administrators. The attack, which leverages browser-in-the-browser (BitB) attacks, has been linked to multiple downstream clients and could result in significant financial losses for affected businesses.
The phishing operation uses fake websites that mimic popular AI products such as ChatGPT, Gemini, Claude, and Perplexity. These sites claim to help advertisers reach buyers, obtain ad briefs, and plan and audit advertising campaigns and spending. To get the benefits, users are asked to connect their account to the fake AI product by clicking on a “connect” button. However, this action opens a fake Google window inside the page, complete with an address bar showing accounts.google.com.
This is where the BitB attack comes into play. Browser-in-the-browser attacks involve creating a fake browser window inside a legitimate one to display a fraudulent login page. The fake window looks like a login pop-up, featuring realistic titles and interface, but it’s actually just an iframe designed to steal the victim’s credentials. Researchers at Island, a browser security company, have found that the attacker uses a kit that adapts the interface to various operating systems and browsers, including Windows, macOS, iOS, and Android.
Once the victim is in the BitB flow, a human operator takes over the process and controls what the victim is prompted to do next. The attacker may ask for password entry up to three times, request an SMS or authenticator code to bypass MFA protections, display Okta push requests, show Google approval prompts, or display a QR code. Operators can also reject codes submitted by the victims, hold them in a waiting screen, and finish or suppress the phishing flow at any time.
But that’s not all – researchers have found that this is part of a larger operation that used multiple lures, such as fake recruitment opportunities and refund pages. The connection to the larger operation was possible because the attacker exposed older source code through misconfigured public GitHub repositories, allowing the activity to be traced as far back as March.
The impact of these attacks could be significant, especially for businesses that rely on advertising revenue. Attackers can spend available balances on fraudulent ad campaigns or resell them to other cybercriminals for profit. It’s essential for advertisers and their teams to be aware of this threat and take steps to protect themselves.
So what can you do to stay safe? Be cautious when connecting your account to any website, especially if it claims to offer AI-powered services. Verify the authenticity of the site and look out for telltale signs of a BitB attack, such as an iframe that cannot be moved outside the browser window or resized. Always use strong passwords and MFA whenever possible, and keep your software up-to-date to prevent exploitation of known vulnerabilities. By being vigilant and taking these precautions, you can reduce the risk of falling victim to this type of attack.
Source: Bleeping Computer — 2026-10-06