HomeSecurityNew campaign with fake AI tools steals ad accounts

New campaign with fake AI tools steals ad accounts

A new phishing campaign is using fake AI tools to impersonate ad management services. It aims to steal passwords and multi-factor authentication (MFA) data, gaining access to ad accounts that often span multiple clients, according to research by the Island security team.

Fake AI tools steal accounts

The fake tools appear as services for ChatGPT, Gemini, Claude, Perplexity, and Manus. They promise campaign optimization, cost control, or connection to advertising accounts. The latest version, called Muse Ads, appeared a few days after Meta unveiled Muse.

The “Login” prompt acts as a trap: instead of opening a real login window, the website draws a fake window within the page. It displays a legitimate-looking address, while the real browser tab remains on the attackers’ website. The Hacker News reports that the method targets passwords and MFA credentials.

The Island team describes the technique as “Browser-in-the-Browser.” The fake form may mimic the appearance of well-known login services, but it is not a separate browser window. So the address the victim sees in the form does not prove who controls the real website.

The platform adapts the appearance on desktop and mobile devices, while a campaign operator monitors the process in real time. They can reject a code, request a retry, or choose which verification request to display next. BleepingComputer notes that the window is part of the website and not a genuine pop-up.

The false window is controlled by an operator

When the visitor clicks the login button, the page captures device information, such as the IP address and screen characteristics, and sends it to the attackers’ infrastructure. The attackers then attempt to log in to the real account and adjust the flow based on the service’s response.

The operator can repeatedly ask for the password, display a request for an SMS or app verification code, a Google approval notification, or a request from Okta. As the attack adapts to the user's responses, simply enabling MFA alone is not enough to prevent the exploit.

The same infrastructure is used for other deceptive pages, including Google refund promises and fake job ads. Researchers found a common technology base and code from older versions in misconfigured public repositories. BleepingComputer reports hundreds of submissions to the perpetrators’ control channel, a number that does not equate to the same number of verified accounts.

See also: What happens when a chatbot gains access to an employee's corporate email?

How fake tools gain access

The main targets are advertising agency employees, media managers, and account managers who have access to multiple clients. Such an employee's access can open the way to advertising budgets, saved payment methods, and campaigns of different businesses.

Compromised customer advertising accounts

Once they gain access, attackers can add their own administrators, remove privileges from the legitimate owner, and use the account for unauthorized campaigns. Recovery can prove more difficult than canceling a card because connected customers are also affected.

The fake tools do not exploit any ChatGPT, Google, or Meta vulnerabilities. They rely on misleading the user and displaying a convincing form, as Island's primary research. Therefore, this is not a problem that can be addressed with a software update.

See also: ChatGPT Phishing: Hackers steal passwords through fake notifications

Address verification and stronger verification

Employees should check the actual browser address bar and open new services from the provider's official website, not from an email invitation. A login window that cannot be moved outside the browser frame or resized may be part of the website.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Organizations should prefer access keys or hardware security keys, which tie verification to the actual website and limit the value of compromised passwords. The SecNews technical team also recommends checking for new administrators, recovery details changes, and unapproved campaigns.

Secure connection with access key

Attackers are leveraging the trust in well-known AI names, as well as the broad reach of advertising accounts. For administrators, the safest option is to verify each login independently and treat each new login request as a grant of access.

See also: Phishing campaign impersonates leading companies and steals accounts

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS