Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Chrome window on gemini-beta-invites.com showing a second, fake Chrome window inside the page with a lock icon, an accounts.google.com address bar and a Google Sign in form.
Screenshot: Island, clicking Connect on a spoofed Gemini Ads page opens a fake Google sign-in window drawn inside the page while the real address bar still shows gemini-beta-invites.com, Oct 6, 2026 (fair use).

Threat Intel

Fake ChatGPT and Gemini Ad Portals Use Browser-in-the-Browser Pop-Ups to Steal Logins and MFA Codes

Island researchers said on October 6 that a human-operated phishing platform posing as AI advertising products for Gemini, ChatGPT, Claude, Perplexity and a fake Muse Ads draws a counterfeit Google sign-in window inside the page, then lets a live operator choose which MFA prompt the victim sees next.

Priya Shah, Threat IntelSingapore5 min read

SINGAPORE - A phishing operation aimed at the people who run corporate advertising accounts is dressing itself up as a line of AI products, and the sign-in window it shows victims is not a window at all, researchers at the browser security company Island said on Tuesday. Pages posing as advertising tools for Gemini, ChatGPT, Claude, Perplexity and Manus, and most recently a fake "Muse Ads," all lead to the same button: Connect. "Clicking it opened a browser drawn inside the real browser," wrote Oleg Zaytsev and Ofek Ronen of Island. "The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain." For security operations teams, the report matters less for the lure than for what sits behind it: a live operator who decides, step by step, which multifactor prompt the victim sees next.

The newest lure moved with the news. Meta introduced Muse as a personal AI agent on September 8, according to Island, and by September 16 the domain museads.ai was presenting a product it called "Your AI ads manager for paid media workflows." Each brand gets its own pitch. The fake ChatGPT page promises a Monday Google Ads brief, the Gemini page promises support for manager accounts and linked clients, and the Perplexity page offers campaign planning and spend audits. The copy is written in advertiser shorthand like MCC and ROAS, Island said, "so a request to connect an account feels routine." Invitation emails that send victims to these pages have been documented by IRONSCALES and Intezer, the researchers added.

Fake Meta Muse landing page headed Your AI ads manager for paid media workflows, with blue Connect buttons in the header and in a chat-style prompt box.
Screenshot: Island, the spoofed Muse Ads page that appeared eight days after Meta announced Muse, captured Sept 19, 2026 (fair use).The spoofed Muse page asks the visitor to connect an ad account.

The technique behind the Connect button is known as browser-in-the-browser. Instead of opening Google, the page draws a second Chrome window inside itself, with a lock icon and an address bar reading accounts.google.com, while the real address bar still shows the phishing domain. BleepingComputer, reporting on the research, noted that the method was devised by a security researcher in March 2022 and that the fake window is an iframe. Island said the kit adapts to Windows, macOS, iOS and Android, and newer builds copy small details such as Safari's URL pill, Chrome's custom tabs and dark mode. One comment left in the code explains that without a frosted toolbar effect, "the chrome looks painted-on and gives away the fake."

The window is only the presentation layer. When a visitor clicks Connect, the page creates a record through an endpoint at /api/create/user, fingerprints the device from IP address and location down to screen size and WebGL, and sends that profile to /api/send/ip, Island said. The platform stores up to three separate password attempts, so an operator can reject an entry, ask the victim to try again and keep every value. Commands arrive over Socket.IO events named operator-command and telegram-command, with a vocabulary that includes /2fa to request an SMS code, /authApp for an authenticator code, /googlePrompt and /oktaApprove for push approvals, /wrong2fa to reject a code, /done to finish and /ban to suppress the page for a visitor. Google, Meta, TikTok and Okta sign-in flows are supported. "Unlike a transparent reverse-proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs," the researchers wrote. That makes the traffic look like an AI product talking to an unrelated application backend, not a session passing through a known identity-provider proxy.

Three-panel Island diagram: Muse Ads phishing page with a browser-in-the-browser Google sign-in, a Socket.IO live session control backend, and an attacker operator receiving password and MFA via Telegram while performing a manual Google login.
Graphic: Island, how the fake Muse Ads flow relays a victim's Google login over Socket.IO to an operator who signs in manually, Oct 6, 2026 (fair use).The operator drives the session over Socket.IO and signs in manually.

The same machinery serves more than advertising. Island said AI ad pages, refund claims and fake job sites all run on one Next.js and Socket.IO stack, calling the same endpoints, with many front ends hosted on Vercel and back ends on Railway or Render. One back end, backend-production-6d75.up.railway.app, appeared in 73 archived scans across 25 page domains between May 27 and June 20, serving Gemini, OpenAI and Anthropic ad lures as well as refund pages and a fake Louis Vuitton careers site. The operators exposed older versions of the platform's source code through misconfigured public GitHub repositories, Island said, including recruitment builds with Telegram wired in as the control channel. While tracking the campaign, the researchers saw hundreds of victim submissions, and the activity was still under way when they published. BleepingComputer cautioned that the submission count does not necessarily reflect the number of accounts successfully taken over.

Grid of twelve phishing page captures in three rows labeled AI Ads, Refund and Recruit, including fake Claude, Muse, Perplexity and Gemini ad pages, Google Ads refund and suspension pages, and fake Tesla, Louis Vuitton, Nike and Adecco careers pages.
Screenshot: Island, spoofed front ends from one platform across three lanes: AI ads, refund and payment pages, and fake recruitment sites, Oct 6, 2026 (fair use).The same stack serves AI ad, refund, and recruitment pages.

The targets are chosen for what their accounts can spend. An advertising account carries a stored payment method and an approved budget, and a manager account can reach several client accounts, each with its own billing profile, Island said. Citing research by Mimecast, the report said attackers either run their own campaigns on a stolen account's budget or sell it, and that aged accounts with a clean spend history sell on Telegram for two to four times the price of new ones. Recovery is the hard part: attackers typically add their own administrators and downgrade the legitimate owner. The recruitment lures aim at a different prize, Island noted, because a job seeker may sign in with a work Google or Okta identity that opens a current employer's email, files and software-as-a-service apps.

Island sells an enterprise browser and closes its report by pitching it, but most of its guidance can be put to work without it. The researchers suggested correlating a client-side pattern that includes google_uid, repeated password fields, calls to api.ipify.org and ipapi.co, the /api/send/ip and /api/create/user paths, and Socket.IO connections to unrelated Railway or Render hosts, and hunting for the control vocabulary itself, such as add-user, update-user, operator-command and telegram-command, which they called more useful than commodity hosting addresses. They urged origin-bound passkeys and hardware-backed authentication, which remove the reusable password and one-time code this platform is built to collect. After any exposure, they said, teams should check every client account the identity could reach for new managers or partners, changed recovery details and campaigns or spending nobody approved. The report lists the ad, refund and recruitment domains tied to the operation. "A page can draw an address bar, lock icon, browser tab, QR prompt, or security dialog," Island wrote. "It cannot change the real browser origin."

Sources:


Priya Shah covers threat intelligence, intrusion analysis, and adversary tradecraft for SOCtember from Singapore.

Related stories

Threat Intel desk