Fake AI sites target ad account managers to steal steal passwords and MFA codes

 

Fake AI sites target ad account managers to steal steal passwords and MFA codes

Cybercriminals are targeting advertising professionals with fake versions of popular AI services such as ChatGPT, Gemini, Claude, and Perplexity. The phishing campaign is designed to steal passwords and multi-factor authentication (MFA) codes.

Researchers at cybersecurity company Island said the campaign also takes advantage of interest in Meta’s new Muse AI agent. The fake websites claim to help advertisers plan campaigns, find buyers, and manage advertising budgets.

When victims try to connect their accounts, the sites display a fake Google login window. The window looks real but is actually built into the webpage using a technique known as browser-in-browser (BitB). This allows attackers to collect login details without opening a real Google login page.

Attackers can then request passwords, SMS or authenticator codes, Okta approval requests, Google confirmations, or QR codes. Human operators control the process and can ask victims to repeat information or wait while the attack continues.

The campaign mainly targets advertising agencies, media buyers, and account administrators because their accounts can provide access to multiple clients and large advertising budgets.

Researchers found links between the campaign and other phishing operations, including fake job offers and refund pages. They also discovered hundreds of victim submissions in a Telegram channel used to control the attacks.

Back to the list