# New Phishing Campaign Mimics AI Advertising Tools to Steal Credentials and Control Ad Accounts
Cybersecurity experts have uncovered an advanced phishing operation that leverages the growing popularity of AI-powered advertising tools to deceive users into surrendering their login credentials and multi-factor authentication codes. The campaign creates convincing imitation websites that replicate the branding and functionality of well-known AI chatbot platforms, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and a service called Manus.
## How the Attack Works
The phishing infrastructure operates as a comprehensive platform designed to deceive even cautious users. Each imitation site presents itself as a legitimate advertising optimization tool, offering services such as campaign performance audits, budget spend analysis, and business account integration. The sites use a deceptive browser-in-the-browser technique to create fraudulent login windows that appear authentic.
When a user visits one of these pages, they encounter a prominent “Connect” button. Clicking this triggers the creation of a fake browser window embedded within their actual browser. This counterfeit window displays a trusted domain name in its address bar — such as accounts.google.com or an Okta tenant URL — while the user remains on the attacker-controlled phishing site. The deceptive address bar tricks users into believing they are signing into a genuine service.
## Credential Harvesting and Device Fingerprinting
Behind the scenes, every password entered by the victim is captured and stored by the attackers. The platform simultaneously collects detailed device fingerprints, including browser characteristics, screen resolution, operating system data, and other identifying markers. This information is transmitted to the attacker in real time through a WebSocket connection to an endpoint on the phishing server.
The real-time nature of the attack allows human operators to interact with victims directly. Once credentials are captured, the attacker attempts to log in to the compromised account immediately. If a multi-factor authentication prompt appears, the attacker can dynamically select which type of MFA challenge to present to the victim, increasing the likelihood of a successful breach.
## Brand-Specific Lures and Targeted Pitches
Each imitation platform tailors its messaging to the specific AI brand it is impersonating. The ChatGPT-themed site promises a weekly Google Ads performance brief. The Gemini-themed site advertises support for manager accounts and linked client configurations. The Claude-themed page features its own advertising portal interface. Perplexity’s copy highlights campaign planning tools and spend audit capabilities. The Manus impersonation offers a dedicated integration for Meta advertising workflows.
Users are typically funneled toward these phishing pages through fraudulent invitation emails that closely replicate the branding and communication style of the legitimate companies. These emails create a sense of urgency and trust, encouraging recipients to click through to the fake platforms.
## Broader Phishing Ecosystem
The AI advertising phishing sites are just one component of a larger operation. Security researchers have identified that the same infrastructure also hosts pages themed around Google Ads refund claims and payment confirmations, as well as recruitment-focused pages targeting job seekers with fake opportunities at well-known companies like Tesla, Louis Vuitton, Nike, and Adecco.
All of the malicious websites share a common technical foundation, built using the Next.js framework and the Socket.IO real-time communication library. They communicate with identical server endpoints, confirming they are operated by the same threat actors. Strikingly, earlier versions of the phishing platform’s source code have been made publicly available through misconfigured GitHub repositories, potentially enabling other criminals to deploy similar campaigns.
## Motives and Consequences
The primary targets of this campaign appear to be advertising agency employees, media buyers, and administrators of manager accounts. By gaining access to these accounts, attackers can monetize the ad budgets by running their own unauthorized campaigns or selling the compromised accounts on underground marketplaces — particularly accounts with a clean spending history and established reputation.
Recovering a stolen advertising account is far more difficult than replacing a compromised payment card. Attackers typically elevate their own access to administrator level while demoting or removing the legitimate account owner. The recovery process can stretch from weeks to months, during which time the compromised account continues to serve unauthorized advertisements and drain budgets. For manager accounts that oversee multiple client accounts, the damage multiplies, affecting entire agencies and their customers.
## Protective Measures
Organizations can reduce their exposure to these threats by implementing several key security practices. Enabling phishing-resistant authentication methods — such as hardware security keys or passkeys — dramatically reduces the effectiveness of credential theft. Regularly auditing advertising account control changes helps detect unauthorized access before significant damage occurs. Additionally, IT teams and employees should carefully vet any AI integrations or third-party tools before authorizing account connections.
## FAQ
**What is a browser-in-the-browser (BitB) attack?**
A BitB attack is a technique where threat actors create a simulated browser window within a real web browser. This fake window displays a legitimate-looking address bar and login form, making users believe they are interacting with a genuine website when they are actually on a phishing page.
**How do attackers obtain multi-factor authentication codes?**
The phishing platform allows human operators to monitor login attempts in real time. When an MFA prompt is triggered during the attack, the operator selects the appropriate challenge type to present to the victim, prompting them to enter their MFA code directly into the fraudulent interface.
**Why are AI-themed advertising tools particularly effective for phishing?**
The rapid adoption of AI tools has created widespread trust and curiosity among professionals. By impersonating these popular platforms, attackers exploit users’ familiarity and willingness to connect accounts for productivity purposes.
**Can stolen advertising accounts be recovered?**
Recovery is possible but extremely challenging. Legitimate account owners must navigate lengthy support processes, prove their identity, and remove unauthorized administrator access. During the recovery period, attackers continue to exploit the account.
**What should I do if I suspect my advertising account has been compromised?**
Immediately change your password, revoke all active sessions, review recent account activity, check for unfamiliar administrator accounts, and contact the platform’s support team to initiate a security investigation.
## Conclusion
This phishing campaign underscores the evolving sophistication of cybercriminal operations that exploit emerging technologies and trusted brands. By combining realistic imitation websites, real-time human manipulation, and advanced technical deception, attackers are successfully compromising advertising accounts at scale. Vigilance, strong authentication practices, and ongoing security awareness remain essential defenses against these persistent threats.
Thank you for reading



