Cybercriminals are using fake versions of popular AI chatbots to steal sensitive information from advertising account managers, including login credentials and multi-factor authentication (MFA) codes. The phishing campaign, which has been ongoing since March, leverages a browser-in-the-browser (BitB) attack technique that creates a fake login window inside a legitimate one.
Researchers at Island, a browser security company, have been tracking the campaign and have identified several key aspects of how it works. The attackers create fake websites that mimic popular AI products such as ChatGPT, Gemini, Claude, and Perplexity. These sites claim to help advertisers reach buyers, obtain ad briefs, and plan and audit advertising campaigns and spending. To “connect” their account to the fake AI product, victims are prompted to enter their login credentials.
However, what appears to be a simple login process is actually a sophisticated phishing technique. The fake website uses an iframe to display a fake browser window that looks like a legitimate login page. This window is designed to steal the victim’s credentials and MFA codes, which can then be used to gain access to advertising accounts. Once the attacker has obtained the necessary information, they use it to carry out fraudulent ad campaigns or resell the compromised accounts to other cybercriminals.
The researchers have found that the attackers are using a kit that adapts the interface of their fake website to match the operating system and browser being used by the victim. This means that whether you’re on Windows, macOS, iOS, or Android, the fake login window will look convincing enough to fool even the most security-conscious individuals.
One of the most concerning aspects of this campaign is its use of human operators to control the phishing process. Once a victim has entered their credentials and MFA codes, they are prompted to perform various actions by a human operator who can reject or accept the submitted information at will. This means that even if a victim is able to detect the phishing attempt and enter incorrect information, the attacker may still be able to bypass security measures.
The researchers have also identified a larger operation behind this campaign, which uses multiple lures such as fake recruitment opportunities and refund pages to trick victims into divulging their sensitive information. The attackers have exposed older source code through misconfigured public GitHub repositories, allowing the activity to be traced back to March.
Fortunately, BitB attacks are relatively easy to uncover, as iframes cannot be moved outside the browser window or resized like a legitimate OAuth popup. This means that security-conscious individuals can take steps to protect themselves by being cautious when clicking on links or entering sensitive information into fake login windows.
To avoid falling victim to this type of phishing attack, it’s essential to be vigilant and skeptical when interacting with unfamiliar websites or AI products. Always verify the authenticity of a website or product before entering sensitive information, and never click on links from unknown senders. By being aware of these types of threats and taking simple precautions, you can protect yourself and your organization from falling prey to cybercriminals who use sophisticated phishing techniques to steal sensitive information.
Source: Bleeping Computer — 2026-10-06