Fake AI ad portals use browser-in-the-browser to steal MFA codes
According to The Hacker News, researchers at Island have described a “human-operated phishing platform” that poses as advertising products for AI chatbots, including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse and Manus. The sites use a browser-in-the-browser phishing trick to capture credentials and multi-factor authentication (MFA) codes. No CVE is involved, and the report does not mention a patch or a CISA KEV entry.
What we know
The report comes from Island researchers Oleg Zaytsev and Ofek Ronen, who shared it with The Hacker News. Each fake product claims to offer things like campaign optimization, spend audits and business-account connections, and each is built around one action: a “Connect” button.
One example is museads[.]ai, which appeared on September 16, 2026, a little over a week after Meta launched its Muse AI agent. It describes itself as an AI ads manager for paid media workflows and shows a prompt box with a Connect button.
Clicking Connect opens what looks like a sign-in window. In fact it is a window drawn inside the real browser page (the browser-in-the-browser, or BitB, technique). Its fake address bar shows a trusted origin such as accounts.google.com or an Okta tenant, while the real browser stays on the phishing domain. The fake form targets Google, Meta, TikTok and Okta sign-in workflows.
Behind the page, the researchers say the platform:
- keeps every password attempt;
- fingerprints the victim’s device and sends the data to the attacker over Socket.IO at the endpoint
/api/send/ip; - lets an operator choose which MFA challenge the victim sees next;
- lets the attacker try the stolen credentials in real time.
Each brand gets its own pitch, according to the researchers: ChatGPT promises a Monday Google Ads brief, Gemini promises manager account (MCC) and linked-client support, Claude gets its own advertising portal, Perplexity offers campaign planning and spend audits, and Manus offers a private Meta integration. Island says the pages also follow the news.
Who is affected
Anyone who runs or has access to advertising or business accounts could be targeted, especially staff who manage Google, Meta, TikTok or Okta-protected accounts. Users are assessed to reach the landing pages through fake invitation emails that impersonate the trusted brands. The number of victims has not been disclosed.
Island says the AI ad pages are one part of a broader platform with a three-pronged operation. The other two are Google Ads-themed refund claims and payment confirmations, and recruitment-themed sites for Tesla, Louis Vuitton, Nike and Adecco.
What has not been confirmed
- Who operates the platform has not been disclosed in the material available to us.
- How many accounts were compromised has not been disclosed.
- The routing through fake invitation emails is described as an assessment, not a confirmed fact.
- Our source text is a partial excerpt of The Hacker News article, so further details in the full report or Island’s original research may exist.
Why this matters
Analysis, not new reporting. BitB pages defeat the usual advice to check the address bar, because the bar the victim sees is part of the page. Because an operator picks the MFA challenge live, ordinary one-time codes and push approvals can be relayed to the attacker as they are entered. Ad accounts carry spending power and access to linked client accounts, so a single compromised marketer can become a wider incident. Treat any report of a user entering credentials into such a page as an account compromise, not a near miss.
What to do
- Warn marketing, agency and finance staff about invitations to connect an account to a new AI ads or campaign tool. Check the sender and the product through a channel you trust, not through the email link.
- Prefer phishing-resistant MFA such as FIDO2 security keys or passkeys, which are bound to the real site and do not hand over a code to a fake window.
- Have users open ad platforms and identity providers from saved bookmarks or the vendor’s own app rather than from email links.
- Check that a sign-in window is a real browser window: a genuine pop-up can be moved outside the page boundary, a drawn one cannot.
- If someone entered credentials on a suspicious page, reset the password, revoke active sessions and tokens, review recent sign-ins and MFA changes, and check linked ad and manager accounts for unexpected access or spend.
Hunting and detection ideas
- Search mail logs for invitations that mention AI ad tools, campaign optimization or spend audits from unfamiliar senders.
- Search proxy or DNS logs for museads[.]ai and for requests to
/api/send/ipon unfamiliar hosts. - Look in identity provider logs for sign-ins soon after a user visited a new, recently registered domain, and for sign-ins from a different device or location than the user’s usual one, followed by MFA method changes.
museads[.]ai /api/send/ip
Sources
Related free tool: test how long a password would take to crack with our Password Strength Checker. It runs entirely in your browser and nothing you type is sent or stored.
